The Insert Pages WordPress plugin before 3.7.5 does not...
        
  Moderate severity
        
          Unreviewed
      
        Published
          Jan 16, 2023 
          to the GitHub Advisory Database
          •
          Updated Jan 25, 2023 
      
  
Description
        Published by the National Vulnerability Database
      Jan 16, 2023 
    
  
        Published to the GitHub Advisory Database
      Jan 16, 2023 
    
  
        Last updated
      Jan 25, 2023 
    
  
The Insert Pages WordPress plugin before 3.7.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
References