The searchterms-tagging-2 plugin through 1.535 for WordPress has XSS via the wp-admin/options-general.php count parameter.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://wordpress.org/plugins/searchterms-tagging-2/#developers | third party advisory |
http://cinu.pl/research/wp-plugins/mail_d14e213879cd60e80e538bde21c0359b.html | third party advisory exploit |