The ActivityPub WordPress plugin before 1.0.0 does not escape user metadata before outputting them in mentions, which could allow users with a role of Contributor and above to perform Stored XSS attacks
2023-10-16T20:15:17.573
2024-11-21T08:40:59.393
Modified
CVSSv3.1: 5.4 (MEDIUM)
-
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | automattic | activitypub | < 1.0.0 | Yes |