Cross-Site Scripting security vulnerability
-
IMPORTANT:
Tabs – Responsive Tabs with WooCommerce Product Tab Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.0.6 due to insufficient input sanitization and output escaping.
This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
https://patchstack.com/database/vulnerability/vc-tabs/wordpress-tabs-plugin-4-0-6-cross-site-scripting-xss-vulnerability
Please fix this ASAP and alert users once repaired.
- You must be logged in to reply to this topic.