CVE-2023-3746

Publication date

2023-10-16 19:39:14

Family

WPScan

State

PUBLISHED

Description

The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allow contributor and above role to perform Stored Cross-Site Scripting attacks