CVE-2024-8914 | haibasoft Thanh Toán Quét Mã QR Code Tự Động Plugin up to 2.0.1 on WordPress wp_kses_allowed_html onclick cross site scripting (EUVD-2024-49648)
A vulnerability was found in haibasoft Thanh Toán Quét Mã QR Code Tự Động Plugin up to 2.0.1 on WordPress. It has been rated as problematic. Affected by this vulnerability is the function wp_kses_allowed_html. Performing manipulation of the argument onclick results in cross site scripting.
This vulnerability is known as CVE-2024-8914. Remote exploitation of the attack is possible. No exploit is available.