PT-2026-60406 · WordPress · Rpb Chessboard
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
RPB Chessboard versions prior to 8.1.3
Description
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting. Attackers can inject arbitrary web scripts into pages that execute when a user accesses them. This occurs because the plugin's
comment text() filter synthesizes attribute-breaking HTML at render time, bypassing WordPress's save-time kses sanitization by using allowed tags and attributes, such as <a> elements with title and href attributes.Recommendations
Update RPB Chessboard to version 8.1.3 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rpb Chessboard