WordPress Plugin Vulnerabilities
TC Custom JavaScript < 1.2.2 - Unauthenticated Stored Cross-Site Scripting (XSS)
Description
A stored Cross-Site Scripting (XSS) vulnerability in the TC Custom JavaScript plugin for WordPress allows unauthenticated remote attackers to inject arbitrary JavaScript via the tccj-content parameter. This is displayed in the page footer of every front-end page and executed in the browser of visitors.
Affects Plugins
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Matt Rusnak/Ramuel Gall/Wordfence
Submitter
Ramuel Gall
Verified
No
WPVDB ID
Timeline
Publicly Published
2020-07-21 (about 5 years ago)
Added
2020-07-21 (about 5 years ago)
Last Updated
2020-07-23 (about 5 years ago)