Cross-Site Request Forgery (CSRF) vulnerability in PluginsPoint Kento Splash Screen kento-splash-screen allows Stored XSS.This issue affects Kento Splash Screen: from n/a through <= 1.4.CreditsNguyen Xuan Chien | Patchstack Bug Bounty ProgramReferenceshttps://patchstack.com/database/Wordpress/Plugin/kento-splash-screen/vulnerability/wordpress-kento-splash-screen-plugin-1-4-cross-site-request-forgery-csrf-to-stored-xss-vulnerability?_s_id=cve