Loading vulnerability details…
CVSS v3.1
5.4
EPSS
0.40%
Published
Jan 16, 2024
Modified
Jun 20, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The Voting Record WordPress plugin through 2.0 is missing sanitisation as well as escaping, which could allow any authenticated users, such as subscriber to perform Stored XSS attacks
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NWeaknesses (CWE)
Affected Products (1)
References (4)