- Lana Codes
- Common Vulnerabilities
Simple Tooltips by Justin Saad <= 2.1.3 - Contributor+ Stored XSS
LANACOMMONVDB ID: 9653c87b-7d22-4a72-8c19-6be67d2b4aea
The plugin does not sanitize and escapes some parameters, which could allow users with a role as low as contributor to perform Cross-Site Scripting (XSS) attacks.
You must be log in to view vulnerability details.
Or register a new account.