Feb. 21, 2023, 9:15 a.m. |

National Vulnerability Database web.nvd.nist.gov

The Login Logout Menu WordPress plugin through 1.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

attacks attributes back cross-site cve escape login logout plugin role scripting wordpress wordpress plugin

Sr. Product Manager

@ MixMode | Remote, US

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Product Security Engineer

@ ServiceNow | Hyderabad, India

Senior Application Security Engineer (Puerto Rico)

@ RTX | HPR99: Field Office – PR, Remote Location, Remote City, PR, 00921 USA