The Jetpack CRM WordPress plugin before 5.4.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
2022-12-12T18:15:11.887
2025-04-22T15:16:01.110
Modified
CVSSv3.1: 4.8 (MEDIUM)
-
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | automattic | jetpack_crm | < 5.4.3 | Yes |