Required CVE Record Information
Description
The Auto iFrame WordPress plugin before 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Credits
- WPScan coordinator
References 1 Total
- https://wpscan.com/vulnerability/487facf7-8880-48b3-b1b2-0d09823d3c46/ exploitvdb-entrytechnical-description