Vulnerabilities > Urosevic > Stock Ticker > 3.23.4

DATE CVE VULNERABILITY TITLE RISK
2024-06-29 CVE-2024-6363 Cross-site Scripting vulnerability in Urosevic Stock Ticker
The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stock_ticker shortcode in all versions up to, and including, 3.24.4 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
urosevic CWE-79
5.4