WordPress Plugin Vulnerabilities

TC Custom JavaScript < 1.2.2 - Unauthenticated Stored Cross-Site Scripting (XSS)

Description

A stored Cross-Site Scripting (XSS) vulnerability in the TC Custom JavaScript plugin for WordPress allows unauthenticated remote attackers to inject arbitrary JavaScript via the tccj-content parameter. This is displayed in the page footer of every front-end page and executed in the browser of visitors.

Affects Plugins

Fixed in 1.2.2

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Matt Rusnak/Ramuel Gall/Wordfence
Submitter
Ramuel Gall
Verified
No

Timeline

Publicly Published
2020-07-21 (about 5 years ago)
Added
2020-07-21 (about 5 years ago)
Last Updated
2020-07-23 (about 5 years ago)

Other