
CVE-2021-47948 WordPress GetPaid Plugin 2.4.6 contains an HTML injection vulnerability that allows authenticated attackers to inject arbitrary HTML code by exploiting the Help Text … https://www.cve.org/CVERecord?id=CVE-2021-47948
Post summary
The entry announces an HTML injection flaw in WordPress GetPaid Plugin 2.4.6 that lets authenticated users inject arbitrary HTML via the Help Text field.
