Stored XSS Vulnerability in IgniteUp Plugin for WordPress
CVE-2019-17236
6.1MEDIUM
What is CVE-2019-17236?
The IgniteUp plugin for WordPress contains a stored Cross-Site Scripting (XSS) vulnerability in the class-coming-soon-creator.php file. This flaw allows attackers to inject malicious scripts into the application, which may then be executed in the context of users visiting the affected site, posing serious security risks to both site administrators and users. It is crucial for users of this plugin to upgrade to the latest version to mitigate potential exploitation.