CVE-2023-2488

Publication date

2023-06-05 13:38:59

Family

WPScan

State

PUBLISHED

Description

The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2023 does not sanitise and escape various parameters before outputting them back in admin dashboard pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin