A stored cross-site scripting (XSS) vulnerability in the Contact Form 7 Datepicker WordPress plugin will not receive a patch, leaving websites exposed to attacks, WordPress security firm Defiant reports.
Advertise on IT Security News.
Read the complete article: Unpatched Flaw in Discontinued Plugin Exposes WordPress Sites to Attacks