Cross-Site Scripting

Guide tag · 10 matching pages

Wordpress Alert: Stored cross-site scripting in shortcodes

Untrusted shortcode attributes become executable HTML or JavaScript. A page view can run attacker-controlled script.

Wordpress Alert: Stored cross-site scripting in profiles

A user profile field executes code in another user's browser. Viewing the profile may trigger unwanted actions or data theft.

Wordpress Alert: Stored cross-site scripting in comments

A comment carries script-capable content that runs when staff view it. The script can act in the staff member's browser and may expose session data.

Wordpress Alert: Stored cross-site scripting in block attributes

A custom block saves a value that later executes in the editor or public page. Editors or visitors can be affected each time the block renders.

Wordpress Alert: Reflected cross-site scripting in search

A crafted search URL echoes unsafe text into the page. A visitor following the link may execute attacker-controlled script.

Wordpress Alert: Malicious redirects through open-redirect flaws

A site link forwards visitors to an attacker-chosen destination. The trusted domain can be used in phishing links.

Wordpress Alert: DOM-based cross-site scripting in page builders

Builder JavaScript inserts untrusted URL or content data into the page unsafely. The browser executes script even if the server response is static.

Wordpress Alert: Cross-site request forgery against user management

An external page induces an authenticated administrator to change an account. Users or roles may be created, deleted, or changed.

Wordpress Alert: Cross-site request forgery against settings

A signed-in administrator visits an external page that triggers a settings change. Configuration may change without the administrator intending it.

Wordpress Alert: Clickjacking of administrative actions

A third-party page frames an admin screen and tricks a user into clicking it. A legitimate session may carry out an unintended action.