PT-2026-43502 · Garber+1 · Gbi To Print
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GBI To Print version 1.0
Description
Stored Cross-Site Scripting occurs when authenticated attackers with contributor-level access or higher inject arbitrary web scripts into pages. The issue stems from insufficient output escaping in the
gbi toprint shortcode() function, which concatenates the raw value of the div attribute within the gbitoprint shortcode directly into an HTML attribute without using esc attr() or other sanitization methods.Recommendations
Update GBI To Print to a version newer than 1.0.
As a temporary mitigation, restrict the ability of users with contributor-level access to edit pages or use the
gbitoprint shortcode.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gbi To Print