CVEs Blog | G5 Cyber Security

CVE-2015-20106 – The ClickBank Affiliate Ads WordPress plugin through 1.20 does not escape

The ClickBank Affiliate Ads WordPress plugin through 1.20 does not escape its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-20106

Reference (s):

Exit mobile version