The Simple Tooltips WordPress plugin before 2.1.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Score: 0.0
Priority: Unclassified
Score: 0.00238
Percentile:
0.46843
CVSS v3.1 Score: 5.4
Severity: MEDIUM