The Advanced WordPress Reset WordPress plugin prior to 1.6 does not escape some generated URLs before outputting them back in href attributes of admin dashboard pages, leading to Reflected Cross-Site Scripting
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
sigmaplugin advanced wordpress reset |