CVE-2018-8729
15.03.2018, 17:29
Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote attackers to inject arbitrary JavaScript or HTML via a title that is not escaped.
Vendor | Product | Version |
---|---|---|
pojo | activity_log | 𝑥 < 2.4.1 |
𝑥
= Vulnerable software versions
References