Discovered by Jack Misiura on behalf of The Missing Link Security
A self-reflected cross-site scripting (XSS) vulnerability in the WordPress SabaiApps DirectoriesPro plugin 1.3.45 allows attackers who have convinced a site administrator to import a specially crafted CSV file, to inject arbitrary JavaScript or HTML into the subsequent responses generated by the web application.
Successful exploitation of this issue may allow an attacker to perform unauthorised actions in the user’s security context.
Discovered in: 1.3.45
Fixed in: 1.3.46