PT-2026-71008 · WordPress · Patterns Kit
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Patterns Kit WordPress plugin versions prior to 1.0.4
Description
The plugin fails to escape a link attribute before a client-side script inserts it into the page. This allows users with Contributor privileges to store a malicious payload that executes in the browser of any user who views the content and clicks the affected element.
Recommendations
Update the Patterns Kit WordPress plugin to version 1.0.4 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Patterns Kit