The URL Shortener by Myhop WordPress plugin through 1.0.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-07-09T06:00:04.751Z

Updated: 2024-08-01T21:25:02.880Z

Reserved: 2024-06-10T16:14:09.751Z

Link: CVE-2024-5802

cve-icon Vulnrichment

Updated: 2024-08-01T21:25:02.880Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-09T06:15:03.117

Modified: 2024-07-12T15:20:14.610

Link: CVE-2024-5802

cve-icon Redhat

No data.