XSS Vulnerability in WP Customer Reviews Plugin for WordPress
CVE-2016-10901
6.1MEDIUM
What is CVE-2016-10901?
The WP Customer Reviews plugin for WordPress, prior to version 3.0.9, contains a security vulnerability that allows attackers to execute arbitrary JavaScript code via specially crafted input in the admin tools. This Cross-Site Scripting (XSS) flaw can be exploited by unauthorized users, potentially compromising the site's security and accessing sensitive information.