The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site Scripting attacks
This Cyber News was published on www.tenable.com. Publication date: Wed, 20 Mar 2024 22:41:03 +0000