Vulnerabilities (CVE)

Filtered by vendor Utopique Subscribe
Filtered by product Better Comments
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-2404 1 Utopique 1 Better Comments 2024-08-09 N/A 5.4 MEDIUM
The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow low privilege users such as Subscribers to perform Stored Cross-Site Scripting attacks.