Weekly Schedule < 3.4.3 - Authenticated Stored XSS
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.7%
exploitation probability
0.7%top 52% of all CVEs
observed exploitation
nono source reports it
The "Schedule Name" input in the Weekly Schedule WordPress plugin before 3.4.3 general options did not properly sanitize input, allowing a user to inject javascript code using the <script> HTML tags and cause a stored XSS issue
Affected products
Unknown · Weekly Schedule