Beta

Report

Sitewide Notice WP <= 2.2 is vulnerable to Authenticated Stored Cross-Site Scripting (XSS) vulnerability

Administrator
Published
2021-08-01

The Sitewide Notice WP WordPress plugin before 2.3 does not sanitise some of its settings before outputting them in frontend pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVSS

Score:4.8

Severity:Medium

Version: 2.2

There is a patch available in v2.3 and we strongly recommend you update to this version as soon as possible.