WordPress Plugin Vulnerabilities

Add Custom Body Class <= 1.4.1 - Contributor+ Stored Cross-Site Scripting

Description

The plugin does not properly escape the add_custom_body_class parameter before outputting it to the page, allowing users with the role of contributor of higher to inject arbitrary web scripts potentially targeting higher privileged users.

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Francesco Carlucci
Verified
No

Timeline

Publicly Published
2023-10-20 (about 2 years ago)
Added
2023-10-27 (about 2 years ago)
Last Updated
2023-10-27 (about 2 years ago)

Other