Description
WordPress Plugin uCan Post is prone to multiple HTML injection vulnerabilities because it fails to properly sanitize user-supplied input. Attacker supplied HTML and script code could be executed in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks may also be possible. WordPress Plugin uCan Post version 1.0.09 is vulnerable; other versions may also be affected.
Remediation
Edit the source code to ensure that input is properly sanitised or disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Video.js-HTML5 Video Player for Wordpress Cross-Site Scripting (4.5.0)
MySQL CVE-2018-2591 Vulnerability (CVE-2018-2591)
Oracle JRE CVE-2012-5089 Vulnerability (CVE-2012-5089)
MySQL CVE-2015-4866 Vulnerability (CVE-2015-4866)
TwistedHTTP Request Splitting Vulnerability (CVE-2020-10109)