The Resume Builder WordPress plugin up to and including 3.1.1 does not sanitize and escape some parameters related to Resume, which could allow users with a role as low as subscriber to perform Stored XSS attacks against higher privilege users
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
resumebuilder resume builder |