The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://wordpress.org/plugins/custom-field-suite/#developers | product third party advisory release notes |
https://blog.reddy.io/2019/05/30/xss-injection-vulnerability-in-custom-field-suite-wordpress-plugin/ | |
https://wpvulndb.com/vulnerabilities/9273 |