CVE-2023-5229 Information

Description

The E2Pdf WordPress plugin before 1.20.20 does not sanitize and escape some of its settings which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Reference

https://wpscan.com/vulnerability/fb6ce636-9e0d-4c5c-bb95-dde1d2581245

Share on: