Unfiltered HTML Settings in WP ULike Plugin Lead to Stored Cross-Site Scripting Attacks
CVE-2024-7878
4.8MEDIUM
What is CVE-2024-7878?
The WP ULike WordPress plugin before 4.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).