TablePress up to and including 3.2 renders shortcode render options through var_export() without escaping when the shortcode_debug attribute is set. An authenticated attacker with Contributor-level access or above can inject arbitrary JavaScript through a table shortcode attribute, which then executes for any logged-in user who views the page.... Weiterlesen
Intelligence View
⚡ tsecurity.de Intelligence
SOCIAL SHARE CARD GENERATOR