CVE-2022-3135 – The SEO Smart Links WordPress plugin through 3.0.1 does not sanitise and escape some of it …

Vuln ID: CVE-2022-3135

Published:  2022-09-26  13:15:11Z

Description: The SEO Smart Links WordPress plugin through 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Source: NVD.NIST.GOV

 


Date:

Categorie(s):

Tag(s):