Beta

Report

WHMCS Bridge <= 6.3 is vulnerable to Reflected Cross-Site Scripting (XSS) vulnerability

Unauthenticated
Published
2022-01-26

The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back in admin dashboard, leading to a Reflected Cross-Site Scripting

CVSS

Score:6.1

Severity:Medium

Version: 6.3

There is a patch available in v6.4b and we strongly recommend you update to this version as soon as possible.