VYPR

Injection Guard

by Fahadmahmood

CVEs (1)

  • CVE-2025-8046MedAug 14, 2025
    risk 0.40cvss 6.1epss 0.00

    The Injection Guard WordPress plugin before 1.2.8 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers