Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in metaphorcreations Metaphor Widgets allows Stored XSS. This issue affects Metaphor Widgets: from n/a through 2.4.CreditsSOPROBRO (Patchstack Alliance)Referenceshttps://patchstack.com/database/wordpress/plugin/mtphr-widgets/vulnerability/wordpress-metaphor-widgets-plugin-2-4-stored-cross-site-scripting-xss-vulnerability?_s_id=cve