|
| Description: | | The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting issue |
|
| Impact: | | An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed. |
|
| Affected OS: | | Windows, Linux, Others |
|
| Reference: | | https://plugins.trac.wordpress.org/changeset/2661008
|
|