CVE-2021-39325
20.09.2021, 20:15
The OptinMonster WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient input validation in the load_previews function found in the ~/OMAPI/Output.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.6.0.
Vendor | Product | Version |
---|---|---|
optinmonster | optinmonster | 𝑥 ≤ 2.6.0 |
𝑥
= Vulnerable software versions
References