Reflected XSS in wordpress plugin parsi-font v4.2.5
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://wordpress.org/plugins/parsi-font | product |
http://www.vapidlabs.com/wp/wp_advisory.php?v=435 | third party advisory exploit |
http://www.securityfocus.com/bid/93802 | vdb entry third party advisory |