Description
The Reading progressbar WordPress plugin before 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Problem types
CWE-79 Cross-Site Scripting (XSS)
Product status
Any version before 1.3.1
Credits
Krugov Artyom
WPScan
References
wpscan.com/...rability/af2e1249-2b69-47b6-85aa-9a6b30c51936/