Security Advisory

CVE-2020-26672

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-10-16 14:36:19
Last updated 2024-08-04 15:56:04
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Testimonial Rotator Wordpress Plugin 3.0.2 is affected by Cross Site Scripting (XSS) in /wp-admin/post.php. If a user intercepts a request and inserts a payload in "cite" parameter, the payload will be stored in the database.