PT-2026-43512 · Eldougo+1 · Tuxquote
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Tuxquote versions prior to 1.4
Description
The Tuxquote plugin for WordPress contains a Stored Cross-Site Scripting issue. This occurs because the
tuxquote build format() function fails to properly sanitize and escape user-supplied attributes title, align, and width used within the 'TUXQUOTE' shortcode. These attributes are concatenated directly into the rendered HTML without being processed by esc attr() or esc html(). Consequently, authenticated attackers with Contributor-level access or higher can inject arbitrary web scripts into pages, which then execute when a user visits the affected page.Recommendations
Update the plugin to a version later than 1.3.
As a temporary mitigation, restrict the ability of users with Contributor-level access to use the 'TUXQUOTE' shortcode.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tuxquote