Vulnerabilities > Dna88 > Highlight > Low
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-09-06 | CVE-2021-24591 | Cross-site Scripting vulnerability in Dna88 Highlight 0.9.1/0.9.2 The Highlight WordPress plugin before 0.9.3 does not sanitise its CustomCSS setting, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | 3.5 |