CVE-2023-1891
27.06.2023, 14:15
The Accordion & FAQ WordPress plugin before 1.9.9 does not escape various generated URLs, before outputting them in attributes when some notices are displayed, leading to Reflected Cross-Site ScriptingEnginsight
Vendor | Product | Version |
---|---|---|
helpiewp | accordion_\&_faq | 𝑥 < 1.9.9 |
𝑥
= Vulnerable software versions