The wp-eMember WordPress plugin before 10.6.6 does not...
Moderate severity
Unreviewed
Published
Jul 13, 2024
to the GitHub Advisory Database
•
Updated May 6, 2025
Description
Published by the National Vulnerability Database
Jul 13, 2024
Published to the GitHub Advisory Database
Jul 13, 2024
Last updated
May 6, 2025
The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
References