CVE-2022-0376 Information
Jun 07, 2022
cve
Description
The User Meta WordPress plugin before 2.4.3 does not sanitise and escape the Form Name as well as Shared Field Labels before outputting them in the admin dashboard when editing a form which could allow high privilege users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Reference
https://wpscan.com/vulnerability/a3ca2ed4-11ea-4d78-aa4c-4ed58f258932
Share on: