CVE-2022-36282
Published Aug 23, 2022Authenticated (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Roman Pronskiy's Search Exclude plugin <= 1.2.6 at WordPress.
Vendor/product archive
2 CVEs tagged to search_exclude_project / search_exclude — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
Authenticated (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Roman Pronskiy's Search Exclude plugin <= 1.2.6 at WordPress.
search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes.