Multiple XSS Vulnerabilities in Football Pool Plugin for WordPress
CVE-2017-18524
6.1MEDIUM
What is CVE-2017-18524?
The Football Pool plugin prior to version 2.6.5 for WordPress is susceptible to multiple cross-site scripting (XSS) vulnerabilities. These issues may allow unauthorized users to inject malicious scripts into the web application, potentially compromising the security of the affected WordPress sites. Administrators are advised to update to the latest version of the plugin to mitigate these risks.