Vulnerabilities (CVE)

Filtered by vendor Enzipe Subscribe
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-2029 1 Enzipe 1 Prepost Seo 2024-02-28 N/A 4.8 MEDIUM
The PrePost SEO WordPress plugin through 3.0 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)