Name of the Vulnerable Software and Affected Versions:
Employee Directory plugin for WordPress versions up to and including 4.5.1
Description:
The Employee Directory plugin for WordPress is susceptible to Stored Cross-Site Scripting through the `noaccess msg` parameter due to insufficient input sanitization and output escaping. This allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts into pages. These scripts will execute when a user accesses the injected page.
Recommendations:
Update the Employee Directory plugin to a version newer than 4.5.1.