CVE-2022-1915
20.06.2022, 11:15
The WP Zillow Review Slider WordPress plugin before 2.4 does not escape a settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite)
Vendor | Product | Version |
---|---|---|
wpreviewslider | wp_zillow_review_slider | 𝑥 < 2.4 |
𝑥
= Vulnerable software versions