CVE-2022-1336 Information

Description

The Carousel CK WordPress plugin through 1.1.0 does not sanitize and escape Slide’s descriptions which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed

Reference

https://wpscan.com/vulnerability/39e127f1-c36e-4699-892f-3755ee17bab6

Share on: