PT-2026-43500 · Cryptoprijzen+1 · Cryptocurrency Prijsvergelijking Widget
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cryptocurrency Prijsvergelijking Widget version 1.0
Description
Stored Cross-Site Scripting occurs due to insufficient output escaping in the
as get coin shortcode() function. The plugin renders the width and height shortcode attributes directly into the style attribute of an element without using escaping functions like esc attr(). Authenticated attackers with contributor-level access or higher can provide a crafted value to terminate the style attribute and inject arbitrary HTML attributes, allowing the execution of malicious web scripts when a user visits the affected page.Recommendations
Update Cryptocurrency Prijsvergelijking Widget to a version newer than 1.0.
As a temporary mitigation, restrict user permissions to prevent users with contributor-level access from editing pages or posts.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cryptocurrency Prijsvergelijking Widget