AIKIDO-2025-10007

virtual-select-plugin is vulnerable to Cross-site Scripting (XSS)

85

High

virtual-select-plugin JS

AIKIDO-2025-10007: virtual-select-plugin is vulnerable to Cross-site Scripting (XSS) in versions 1.0.20 - 1.0.46.

Cross-site Scripting (XSS)
Vuln in 1.0.20 - 1.0.46
Fixed in 1.0.47
No CVE available
TL;DR

Who does this affect?

How can it be fixed?

Background info

Link to vendor website

Logo
ยฉ 2024 Aikido Security BV | BE0792914919
๐Ÿ‡ช๐Ÿ‡บ Registered address: Coupure Rechts 88, 9000, Ghent, Belgium
๐Ÿ‡ช๐Ÿ‡บ Office address: Gebroeders van Eyckstraat 2, 9000, Ghent, Belgium
๐Ÿ‡บ๐Ÿ‡ธ Office address: 95 Third St, 2nd Fl, San Francisco, CA 94103, US
Any use of the intel.aikido.dev website and content is explicitly subject to Aikido Terms of Use