Vulnerabilities > Youngtechleads

DATE CVE VULNERABILITY TITLE RISK
2023-01-03 CVE-2022-4663 Cross-site Scripting vulnerability in Youngtechleads Members Import 1.4.2
The Members Import plugin for WordPress is vulnerable to Self Cross-Site Scripting via the user_login parameter in an imported CSV file in versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping.
network
low complexity
youngtechleads CWE-79
6.1