Wordpress Alert: DOM-based cross-site scripting in page builders
Builder JavaScript inserts untrusted URL or content data into the page unsafely. The browser executes script even if the server response is static.
What it looks like
Builder JavaScript inserts untrusted URL or content data into the page unsafely.
Why it matters
The browser executes script even if the server response is static.
What to check
Review client-side rendering and avoid treating untrusted text as HTML.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress output escaping.
- Categories: WordPress
- Tags: #WordPress Security, #Cross-Site Scripting