Stored Cross-Site Scripting Vulnerability in WordPress MTG Plugin 1.4.1
The Utilities for MTG plugin for WordPress has a Stored Cross-Site Scripting vulnerability. This happens through the plugin's 'mtglink' shortcode in versions up to 1.4.1. The issue is due to poor input sanitization and output escaping on user-supplied attributes. Authenticated attackers with contributor access or higher can inject harmful web scripts. These scripts run when a user visits a page with the injected code.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
yunra utilities for mtg |