Skip to content
ביקורת אבטחה
חזרה ללוח
D39אומת בקודP0

Stored XSS: buyer `full_name` unescaped in event-guests wp-admin metabox

C · authS2 · active-safeSECT1
תיקון
95%
מורכבות low

A buyer's name is shown unescaped in an admin screen, allowing stored cross-site scripting.

event-leads.php:171