Stored XSS in CC-IMG-Shortcode WordPress Plugin via Shortcode Attributes
The CC-IMG-Shortcode plugin for WordPress version 1.1.0 and earlier has a Stored Cross-Site Scripting vulnerability through its 'img' shortcode. The issue stems from weak input sanitization and output escaping of user-supplied attributes. Attackers with contributor-level or higher permissions can inject malicious web scripts into pages. When a user views an infected page, these injected scripts will automatically execute, potentially compromising the website's security and user experience.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
clearcodehq cc-img-shortcode |