Feb. 6, 2023, 8:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

The Drag & Drop Sales Funnel Builder for WordPress plugin before 2.6.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

amp attacks attributes back builder cross-site cve escape funnel plugin role sales scripting wordpress wordpress plugin

Associate Director Cyber Engineering

@ KBR, Inc. | CO102: 16800 E Centretech Pkwy,Aurora 16800 East Centretech Pkwy Building S75, Aurora, CO, 80011 USA

Application Security Engineering Manager - Security Operations (Boston)

@ Klaviyo | Boston, MA

Azure Security DevOps Engineer

@ Global Payments | North Carolina - Remote

Senior IT Planning Analyst - Cybersecurity PMO

@ Pacific Gas and Electric Company | Oakland, CA, US, 94612

Principal Business Value Consultant

@ Palo Alto Networks | Chicago, IL, United States

Sr. Specialist - Cyber Defence Operations

@ Diageo | Bengaluru Karle Town SEZ