CVE-2023-4290
16.10.2023, 20:15
The WP Matterport Shortcode WordPress plugin before 2.1.7 does not escape the PHP_SELF server variable when outputting it in attributes, leading to Reflected Cross-Site Scripting issues which could be used against high privilege users such as adminEnginsight
Vendor | Product | Version |
---|---|---|
mpembed | wp_matterport_shortcode | 𝑥 < 2.1.7 |
𝑥
= Vulnerable software versions