The Essential Real Estate WordPress plugin prior to 3.9.6 does not sanitize and escapes some parameters, which could allow users with a role as low as Admin to perform Cross-Site Scripting attacks.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
g5theme essential real estate |