CVE-2018-16285
EUVD-2018-813606.09.2018, 23:29
The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/admin-ajax.php.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| userproplugin | userpro | 𝑥 ≤ 4.9.23 |
𝑥
= Vulnerable software versions