Tag
The Presto Player WordPress plugin is vulnerable to Stored Cross-Site Scripting via the presto-player tag, allowing unauthenticated attackers to execute arbitrary web scripts.