The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/114d94be-b567-4b4b-9a44-f2c05cdbe18e | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: WPScan
Published: 2022-06-27T08:59:16
Updated: 2022-06-27T08:59:16
Reserved: 2022-06-06T00:00:00
Link: CVE-2022-1994
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-06-27T09:15:10.623
Modified: 2022-07-06T12:48:39.573
Link: CVE-2022-1994
JSON object: View
Redhat Information
No data.
CWE