The Search & Filter Pro WordPress plugin before 2.5.18...
Moderate severity
Unreviewed
Published
Aug 8, 2024
to the GitHub Advisory Database
•
Updated May 28, 2025
Description
Published by the National Vulnerability Database
Aug 8, 2024
Published to the GitHub Advisory Database
Aug 8, 2024
Last updated
May 28, 2025
The Search & Filter Pro WordPress plugin before 2.5.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
References