CVE-2018-8729
15.03.2018, 17:29
Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote attackers to inject arbitrary JavaScript or HTML via a title that is not escaped.
| Vendor | Product | Version |
|---|---|---|
| pojo | activity_log | 𝑥 < 2.4.1 |
𝑥
= Vulnerable software versions
References