Site icon API Security Blog

WordPress < 6.5.5 – Contributor+ Stored XSS in HTML API

Description WordPress does not properly escape URL attributes in the HTML API, allowing high-privileged users to perform Stored Cross-Site Scripting (XSS)…Read More

Exit mobile version