The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin before 2.4.1 use a third-party library that removes the escaping on some HTML characters, leading to a cross-site scripting vulnerability.
2023-07-10T16:15:48.720
2025-01-06T17:15:10.700
Modified
CVSSv3.1: 6.1 (MEDIUM)
-
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | srbtranslatin_project | srbtranslatin | < 2.4 | Yes |
| Application | updraftplus | wp-optimize | < 3.2.13 | Yes |