Skip to main content
Loading…
    CVE-2023-2337 — The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privile — CVE Database · The Intelligence Room