Security Advisory

CVE-2022-1724

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-06-13 12:42:31
Last updated 2024-08-03 00:16:58
Assigner WPScan
State PUBLISHED

Description

The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting them back in AJAX actions, leading to Reflected Cross-Site Scripting