VYPR

Dynamic Widgets

by Bootstrapped

CVEs (1)

  • CVE-2021-24933MedFeb 28, 2022
    risk 0.35cvss 5.4epss 0.01

    The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an attribute when using the term_tree AJAX action (available to any authenticated users), leading to a Reflected Cross-Site Scripting issue