The MyCryptoCheckout WordPress plugin before 2.124 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.
id: CVE-2023-1546
info:
name: MyCryptoCheckout < 2.124 - Cross-Site Scripting
author: Harsh
s
...