Описание
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wishloop Terms of Service & Privacy Policy Generator allows Stored XSS. This issue affects Terms of Service & Privacy Policy Generator: from n/a through 1.0.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wishloop Terms of Service & Privacy Policy Generator allows Stored XSS. This issue affects Terms of Service & Privacy Policy Generator: from n/a through 1.0.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2025-49413
- https://patchstack.com/database/Wordpress/Plugin/superstorefinder-wp/vulnerability/wordpress-super-store-finder-plugin-7-6-cross-site-scripting-xss-vulnerability?_s_id=cve
- https://patchstack.com/database/wordpress/plugin/terms-of-service-and-privacy-policy/vulnerability/wordpress-terms-of-service-privacy-policy-generator-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve
Связанные уязвимости
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in highwarden Super Store Finder superstorefinder-wp allows Reflected XSS.This issue affects Super Store Finder: from n/a through <= 7.6.