CVE-2019-16524

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
26/09/2019
Last modified:
01/10/2019

Description

The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Menu inc/class-easyfancybox.php due to improper encoding of arbitrarily submitted settings parameters. This occurs because there is no inline styles output filter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:status301:easy_fancybox:*:*:*:*:*:wordpress:*:* 1.8.18 (excluding)