Widget4Call WordPress plugin <= 1.0.7 contains a reflected cross-site scripting caused by unsanitized parameter output in the page, letting attackers execute arbitrary scripts in the context of high privilege users, exploit requires attacker to craft a malicious URL.
id: CVE-2024-13099
info:
name: Widget4Call WordPress - Cross-Site Scripting
author: Sourabh-Sah
...