Description
The WP Logs Book WordPress plugin through 1.0.1 does not sanitise and escape some of its log data before outputting them back in an admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting
Problem types
CWE-79 Cross-Site Scripting (XSS)
Product status
Any version
Credits
Bob Matyas
WPScan
References
wpscan.com/...rability/ab551552-944c-4e2a-9355-7011cbe553b0/
wpscan.com/...rability/ab551552-944c-4e2a-9355-7011cbe553b0/