Discover the details of CVE-2021-38352 affecting Feedify – Web Push Notifications WordPress plugin up to version 2.1.8. Learn about the risks, impact, and mitigation steps for this Reflected Cross-Site Scripting vulnerability.
Feedify – Web Push Notifications WordPress plugin up to version 2.1.8 is vulnerable to Reflected Cross-Site Scripting via the feedify_msg parameter in the ~/includes/base.php file. Attackers can inject arbitrary web scripts using this exploit.