The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/7ed050a4-27eb-4ecb-9182-1d8fa1e71571 | third party advisory exploit |
https://plugins.trac.wordpress.org/changeset/2662665 | third party advisory release notes |