The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin before 2.4.1 use a third-party library that removes the escaping on some HTML characters, leading to a cross-site scripting vulnerability.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Srbtranslatin | Srbtranslatin_project | * | 2.4 (excluding) |
Wp-optimize | Updraftplus | * | 3.2.13 (excluding) |