CVE-2024-4749
04.06.2024, 06:15
The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.
Vendor | Product | Version |
---|---|---|
tipsandtricks-hq | wp_emember | 𝑥 < 10.3.9 |
𝑥
= Vulnerable software versions