Filtered by vendor Opensea Project Subscriptions
Filtered by product Opeansea Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-1228 1 Opensea Project 1 Opeansea 2024-08-02 4.8 Medium
The Opensea WordPress plugin before 1.0.3 does not sanitize and escape some of its settings, like its "Referer address" field, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.