Wordpress Alert: Stored cross-site scripting in shortcodes
Untrusted shortcode attributes become executable HTML or JavaScript. A page view can run attacker-controlled script.
Guide tag · 10 matching pages
Untrusted shortcode attributes become executable HTML or JavaScript. A page view can run attacker-controlled script.
A user profile field executes code in another user's browser. Viewing the profile may trigger unwanted actions or data theft.
A comment carries script-capable content that runs when staff view it. The script can act in the staff member's browser and may expose session data.
A custom block saves a value that later executes in the editor or public page. Editors or visitors can be affected each time the block renders.
A crafted search URL echoes unsafe text into the page. A visitor following the link may execute attacker-controlled script.
A site link forwards visitors to an attacker-chosen destination. The trusted domain can be used in phishing links.
Builder JavaScript inserts untrusted URL or content data into the page unsafely. The browser executes script even if the server response is static.
An external page induces an authenticated administrator to change an account. Users or roles may be created, deleted, or changed.
A signed-in administrator visits an external page that triggers a settings change. Configuration may change without the administrator intending it.
A third-party page frames an admin screen and tricks a user into clicking it. A legitimate session may carry out an unintended action.