CVE-2022-4307
23.01.2023, 15:15
The WordPress plugin before 2.9.3 does not sanitise and escape some parameters, allowing unauthenticated attackers to send a request with XSS payloads, which will be triggered when a high privilege users such as admin visits a page from the plugin.Enginsight
Vendor | Product | Version |
---|---|---|
wp-master | pardakht-delkhah | 𝑥 < 2.9.3 |
𝑥
= Vulnerable software versions