CyberRota Analysis
AI-GeneratedThe geotargetingwp WordPress plugin prior to version 3.5.6.2 is vulnerable due to improper sanitization and escaping of parameters in AJAX responses, which can lead to cross-site scripting (XSS) attacks. This flaw allows unauthenticated attackers to inject malicious scripts that execute in the context of a victim's browser when they interact with a crafted request. WordPress administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation risks.
Original NVD Description
The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before reflecting them back in AJAX responses that are served with an HTML content type, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a victim is tricked into submitting a crafted request.