Wall Display Master Project Plugin does not properly escape the customTheme query parameter, resulting in a reflected cross-site scripting vulnerability.
As of publication of this advisory, there is no fix.
{
"nvd_published_at": "2019-08-07T15:15:00Z",
"github_reviewed_at": "2023-03-03T23:09:55Z",
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"severity": "MODERATE"
}