Filtered by vendor Lesterchan Subscriptions
Filtered by product Wp-useronline Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-5560 1 Lesterchan 1 Wp-useronline 2024-11-21 6.1 Medium
The WP-UserOnline WordPress plugin before 2.88.3 does not sanitise and escape the X-Forwarded-For header before outputting its content on the page, which allows unauthenticated users to perform Cross-Site Scripting attacks.