WordPress Gwyn's Imagemap Selector <=0.3.3 - Cross-Site Scripting
Wordpress Gwyn's Imagemap Selector plugin 0.3.3 and prior contains a reflected cross-site scripting vulnerability. It does not sanitize the id and class parameters before returning them back in attributes.
PoC 已收录gwyns-imagemap-selector
CVSS6.1EPSS 2.2%