Dynamic Widgets, 5dd9d324c9dd9e4f3db52cd08c75f2fb94e77fb5
- CVE, Research URL
- Home page URL
- Application
- Published on
- May 15, 2012
- Research Description
- Dynamic Widgets [dynamic-widgets] < 1.5.2 Dynamic Widgets <= 1.5.1 - Cross Site Scripting The Dynamic Widgets plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected versions
-
max 1.5.2.
- Status
-
vulnerable