WordPress · Xabier Miranda Wp Back Button · CVE-2024-35643
**Name of the Vulnerable Software and Affected Versions**
Xabier Miranda WP Back Button versions 1.1.3 and earlier
**Description**
The issue is a Cross Site Scripting (XSS) vulnerability, specifically a Stored XSS, in Xabier Miranda WP Back Button. This allows an attacker to inject malicious scripts into the application, potentially leading to unauthorized actions on behalf of other users.
**Recommendations**
For Xabier Miranda WP Back Button versions 1.1.3 and earlier, update to a version that contains a fix for this issue, as no specific workaround is provided for these versions.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.