CVE-2022-3420
31.10.2022, 16:15
The Official Integration for Billingo WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users with a role as low as Shop Manager to perform Stored Cross-Site Scripting attacks.
Vendor | Product | Version |
---|---|---|
official_integration_for_billingo_project | official_integration_for_billingo | 𝑥 < 3.4.0 |
𝑥
= Vulnerable software versions