WP Finance WordPress plugin <= 1.3.6 contains a reflected cross-site scripting caused by lack of sanitization and escaping of a parameter before output, letting attackers execute scripts in high privilege users' browsers, exploit requires victim to click a malicious link.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view