The BackupBuddy WordPress plugin before 8.8.3 does not sanitise and escape some parameters before outputting them back in various places, leading to Reflected Cross-Site Scripting
2023-02-21T09:15:11.827
2025-03-14T14:15:13.110
Modified
CVSSv3.1: 6.1 (MEDIUM)
-
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ithemes | backupbuddy | < 8.8.3 | Yes |