A cross-site scripting (XSS) vulnerability in ApolloTheme AP PageBuilder component through 2.4.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the show_number parameter.
| Software | From | Fixed in |
|---|---|---|
| apollotheme / ap_pagebuilder | - | 2.4.4.x |