The RSS for Yandex Turbo WordPress plugin prior to 1.30 did not properly sanitise the user inputs from its ???????? settings tab before outputting them back in the page, leading to authenticated stored Cross-Site Scripting issues
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
wpuslugi rss for yandex turbo |