OSV 1.4.0 · unreviewed · 修改于 2026-08-24 02:31
发布时间
2026-08-22 14:31
GitHub 审查时间
—
NVD 发布时间
2026-08-22 14:16
源文件
advisories/unreviewed/2026/08/GHSA-9jf6-vw36-77hj/GHSA-9jf6-vw36-77hj.json
The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contributor role and above to inject JavaScript that executes in the session of any administrator who opens the affected item.
该公告没有提供结构化的受影响软件包信息。