Description: The plugin fails to properly validate and escape some shortcode attributes. This can be exploited by users with Contributor or higher roles to perform Stored Cross-Site Scripting (XSS) attacks via a page/post containing the shortcode. Affects Plugins: - wordprezi - Fixed in version 0.9 References: - CVE: Not specified - Classification: - Type: XSS - OWASP Top 10: A7 - Cross-Site Scripting (XSS) - CWE: CWE-79 - CVSS: 6.8 (Medium) Miscellaneous: - Original Researcher: Lana Codes - Submitter: Lana Codes - Submitter Website: https://lana.codes/ - Submitter Twitter: lanaCodes - Verified: Yes - WPVDB ID: 6b6f9e42-7f7f-4daa-99c9-14a24a6d76b0 Timeline: - Publicly Published: 2023-01-11 (about 2 years ago) - Added: 2023-01-11 (about 2 years ago) - Last Updated: 2023-03-29 (about 2 years ago)