CVE-2023-4290

Publication date

2023-10-16 19:22:43

Family

WPScan

State

PUBLISHED

Description

The WP Matterport Shortcode WordPress plugin before 2.1.7 does not escape the PHP_SELF server variable when outputting it in attributes, leading to Reflected Cross-Site Scripting issues which could be used against high privilege users such as admin