Name of the Vulnerable Software and Affected Versions:
Mmm Unity Loader plugin for WordPress versions prior to 1.0
Description:
The Mmm Unity Loader plugin for WordPress is susceptible to Stored Cross-Site Scripting via the `attributes` parameter due to insufficient input sanitization and output escaping. This allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts into pages. These scripts will execute when a user accesses the injected page.
Recommendations:
Update the Mmm Unity Loader plugin to a version later than 1.0.