cleantalk
Vulnerabilities and Security Researches

Nested Pages, CVE-2022-1990

CVE, Research URL

CVE-2022-1990

Application

Nested Pages

Published on
Jun 27, 2022
Research Description
The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is disallowed
Affected versions
max 3.1.21.
Status
vulnerable