CVE-2022-1387
No Future Posts <= 1.4 - Admin+ Stored Cross-Site Scripting
The No Future Posts WordPress plugin through 1.4 does not escape its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed
Affected products
Unknown · No Future PostsWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →