Wordpress Alert: Stored cross-site scripting in block attributes
A custom block saves a value that later executes in the editor or public page. Editors or visitors can be affected each time the block renders.
What it looks like
A custom block saves a value that later executes in the editor or public page.
Why it matters
Editors or visitors can be affected each time the block renders.
What to check
Inspect custom block rendering and sanitize allowed HTML before output.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress output escaping, WordPress input sanitizing.
- Categories: WordPress
- Tags: #WordPress Security, #Cross-Site Scripting