FlatPress 1.2.1 contains a stored cross-site scripting vulnerability that allows for arbitrary execution of JavaScript commands through blog content. An attacker can possibly steal cookie-based authentication credentials and launch other attacks.
id: CVE-2021-41432
info:
name: FlatPress 1.2.1 - Stored Cross-Site Scripting
author: arafatansa
...