VYPR

Stock In \& Out

by Stock In \& Out Project

CVEs (1)

  • CVE-2021-24346MedJun 14, 2021
    risk 0.35cvss 5.4epss 0.01

    The Stock in & out WordPress plugin through 1.0.4 has a search functionality, the lowest accessible level to it being contributor. The srch POST parameter is not validated, sanitised or escaped before using it in the echo statement, leading to a reflected XSS issue