VYPR

Product Vendors

by WordPress

CVEs (1)

  • CVE-2017-20193MedOct 16, 2024
    risk 0.31cvss 4.7epss 0.00

    The Product Vendors is vulnerable to Reflected Cross-Site Scripting via the 'vendor_description' parameter in versions up to, and including, 2.0.35 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…