User Avatar - Reloaded < 1.2.2 - Contributor+ Stored XSS
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.5%
exploitation probability
0.5%top 63% of all CVEs
observed exploitation
nono source reports it
The User Avatar WordPress plugin before 1.2.2 does not properly sanitize and escape certain of its shortcodes attributes, which could allow relatively low-privileged users like contributors to conduct Stored XSS attacks.
Affected products
Unknown · User Avatar