Beta

Report

Very Simple Breadcrumb <= 1.0 is vulnerable to Authenticated Stored Cross-Site Scripting (XSS) vulnerability

Administrator
Published
2022-06-19

The Very Simple Breadcrumb WordPress plugin through 1.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS

Score:4.8

Severity:Medium

Version: 1.0

The plugin vendor has not patched this vulnerability at the moment.