top of page

Posts

[WordPress VK All in One Expansion Unit Plugin](versions 9.87.0.1 and older) Vulnerability



[WordPress VK All in One Expansion Unit Plugin](versions 9.87.0.1 and older) Vulnerability to Cross-Site Scripting (XSS)



Importance (CVSS3.0)

★★★★★★★☆☆☆ 7.1/ 10 - High


Details

A Cross-Site Scripting (XSS) vulnerability was discovered in WordPress VK All in One Expansion Unit Plugin.


This vulnerability allows malicious attackers to inject fraudulent scripts such as redirect, ads, and other HTML payload. This may be executed when guests visit the website.


Solutions

Update the WordPress VK All in One Expansion Unit Plugin to the newest version (9.87.1.0 and newer).


Source




We provide information about critical vulnerabilities of WordPress for people who are using or are considering using Wordpress for their projects.




bottom of page