A Contributor-level user could inject arbitrary JavaScript via the menu divider ("menudivider") attribute of the nested navigation menu widget. The injected script executes when a visitor loads any SeedProd-powered page that includes the affected nav-menu block. The fix in `app/nestednavmenu.php` adds `sanitize_text_field()` on the incoming... Weiterlesen
Intelligence View
Authenticated (Contributor+) Stored XSS in Nested Nav Menu Widget
A Contributor-level user could inject arbitrary JavaScript via the menu divider ("menudivider") attribute of the nested navigation menu widget. The injected script executes when a visitor loads any SeedProd-powered page that…
SOCIAL SHARE CARD GENERATOR