WP Finance WordPress plugin <= 1.3.6 contains a reflected cross-site scripting caused by lack of sanitization and escaping of a parameter before output, letting attackers execute scripts in high privilege users' browsers, exploit requires victim to click a malicious link.
id: CVE-2024-13097
info:
name: WP Finance Plugin <= 1.3.6 - Cross-Site Scripting
author: Sourab
...