Security Advisory

CVE-2017-20008

6.1
MEDIUM

Vulnerability Description

The myCred WordPress plugin before 1.7.8 does not sanitise and escape the user parameter before outputting it back in the Points Log admin dashboard, leading to a Reflected Cross-Site Scripting
Published Date November 29, 2021
Official Source NIST NVD Advisory