Custom Field Manager WordPress plugin through 1.0 contains a reflected XSS caused by unsanitized and unescaped parameter output, letting attackers execute scripts against high privilege users such as admin, exploit requires crafted request.
id: CVE-2024-12873
info:
name: Custom Field Manager WordPress - Cross-Site Scripting
author: So
...