BetterLinks < 1.2.6 - Admin+ Stored Cross-Site Scripting
CVE-2021-24812
5.4MEDIUM
What is CVE-2021-24812?
The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Scripting issues when an admin import a malicious CSV.
Affected Version(s)
BetterLinks – Shorten, Track and Manage any URL 1.2.6