cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2024-2846,https://securityvulnerability.io/vulnerability/CVE-2024-2846,Stored Cross-Site Scripting Vulnerability Affects Visual Footer Credit Remover Plugin for WordPress,"The Visual Footer Credit Remover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'selector' parameter in all versions up to, and including, 2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.",Wordpress,Visual Footer Credit Remover,4.4,MEDIUM,0.0004299999854993075,false,,false,false,false,,false,false,2024-05-14T15:21:00.000Z,0