Known CVE
WordPress Calls to Action <=2.4.3 - Authenticated Reflected XSS
Calls to Action plugin before 2.5.1 for WordPress contains stored XSS caused by unsanitized input in open-tab parameter in wp-admin/edit.php and wp-cta-variation-id parameter in ab-testing-call-to-action-example/, letting remote attackers inject arbitrary web script or HTML, exploit requires sending crafted requests.
CVE-2015-8350
Medium2015CVSS 6.1CWE-79
seclists · cve2015 · wordpress · wp-plugin · xss · reflected · authenticated
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website