CVE-2022-1990

Publication date

2022-06-27 08:59:11

Family

WPScan

State

PUBLISHED

Description

The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is disallowed