The Jetpack CRM WordPress plugin before 5.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins
2023-01-09T23:15:28.537
2025-04-09T20:15:24.373
Modified
CVSSv3.1: 5.4 (MEDIUM)
-
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | automattic | jetpack_crm | < 5.5.0 | Yes |