Description
WordPress Plugin uCan Post is prone to multiple HTML injection vulnerabilities because it fails to properly sanitize user-supplied input. Attacker supplied HTML and script code could be executed in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks may also be possible. WordPress Plugin uCan Post version 1.0.09 is vulnerable; other versions may also be affected.
Remediation
Edit the source code to ensure that input is properly sanitised or disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Contact Form 7 Cross-Site Scripting (4.0.1)
Jenkins Protection Mechanism Failure Vulnerability (CVE-2021-21690 )
WordPress Plugin Google Maps by BestWebSoft Multiple Cross-Site Scripting Vulnerabilities (1.2.1)
MySQL CVE-2024-21199 Vulnerability (CVE-2024-21199)
WordPress Plugin Responsive Cookie Consent Cross-Site Scripting (1.7)