CVE-2024-13823
15.05.2025, 20:15
The 360 Product Rotation WordPress plugin through 1.5.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.
Vendor | Product | Version |
---|---|---|
yofla | 360_product_rotation | 𝑥 ≤ 1.5.8 |
𝑥
= Vulnerable software versions