HomeDefault status
unaffected
Any version before 6.1.13
affected
Description
The Simple File List WordPress plugin before 6.1.13 does not sanitise and escape a generated URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against admins.
Problem types
CWE-79 Cross-Site Scripting (XSS)
Product status
Any version before 6.1.13
Credits
tu3n4nh
WPScan
References
wpscan.com/...rability/9ee74a0f-83ff-4c15-a114-f8f6baab8bf5/