CVE-2022-1268

Publication date

2022-05-23 07:15:31

Family

WPScan

State

PUBLISHED

Description

The Donate Extra WordPress plugin through 2.02 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected cross-Site Scripting