Wordpress Alert: Stored cross-site scripting in comments
A comment carries script-capable content that runs when staff view it. The script can act in the staff member's browser and may expose session data.
What it looks like
A comment carries script-capable content that runs when staff view it.
Why it matters
The script can act in the staff member's browser and may expose session data.
What to check
Review comment rendering and escape untrusted output in its HTML context.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress output escaping.
- Categories: WordPress
- Tags: #WordPress Security, #Cross-Site Scripting