N/A Unfixed
2023-07-18≤ 1.2.4
WordPress Internal Comments Plugin <= 1.2.4 is vulnerable to Cross Site Scripting (XSS)
Minimum safe version
1.2.3
Update to 1.2.3 or later to address 2 fixable vulnerabilities
WordPress Internal Comments Plugin <= 1.2.4 is vulnerable to Cross Site Scripting (XSS)
WordPress Internal Comments plugin <= 1.2.2 - Sensitive Information Disclosure vulnerability
WordPress Internal Comments plugin <= 1.2.2 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability