Wordpress Alert: Stored cross-site scripting in profiles
A user profile field executes code in another user's browser. Viewing the profile may trigger unwanted actions or data theft.
What it looks like
A user profile field executes code in another user's browser.
Why it matters
Viewing the profile may trigger unwanted actions or data theft.
What to check
Check profile templates and plugin widgets for context-appropriate escaping.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress output escaping.
- Categories: WordPress
- Tags: #WordPress Security, #Cross-Site Scripting