The InventoryPress WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/3cfcb8cc-9c4f-409c-934f-9f3f043de6fe | third party advisory vdb entry exploit technical description |
https://github.com/daniloalbuqrque/poc-cve-xss-inventory-press-plugin | third party advisory exploit |