Description
An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php weblizar_pffree_settings_save_get-users parameter.
Remediation
References
https://github.com/d4wner/Vulnerabilities-Report/blob/master/weblizar-pinterest-feeds.md
https://wpvulndb.com/vulnerabilities/9009
Related Vulnerabilities
CVE-2022-48285 Vulnerability in maven package org.webjars.npm:jszip
CVE-2020-36049 Vulnerability in maven package org.webjars.npm:socket.io-parser
CVE-2022-25847 Vulnerability in npm package serve-lite
CVE-2016-10538 Vulnerability in npm package cli
CVE-2020-8203 Vulnerability in maven package org.webjars.npm:lodash