Reflected XSS in wordpress plugin new-year-firework v1.1.9
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.vapidlabs.com/wp/wp_advisory.php?v=453 | third party advisory exploit |
https://wordpress.org/plugins/new-year-firework | not applicable |
http://www.securityfocus.com/bid/93817 | vdb entry |