CVE Published: 06/11/2024 |
CVE Updated: 06/11/2024 |
CVE Year: 2024 Source: WPScan |
Vendor: Unknown |
Product: WP ULike Status : PUBLISHED
CVE-2024-7879 Description
The WP ULike WordPress plugin before 4.7.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed