Cross-Site Request Forgery (CSRF) vulnerability in litefeel Flash Show And Hide Box allows Stored XSS.This issue affects Flash Show And Hide Box: from n/a through 1.6.CreditsSOPROBRO (Patchstack Alliance)Referenceshttps://patchstack.com/database/vulnerability/flash-show-and-hide-box/wordpress-flash-show-and-hide-box-plugin-1-6-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve