PT-2026-99247 · WordPress · Wp Delicious
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WP Delicious WordPress plugin versions prior to 1.10.8
Description
Insufficient validation and escaping of HTML tag names derived from user-supplied recipe block data allows users with the Contributor role and above to inject arbitrary HTML tags, including script tags. These tags execute when the recipe page is viewed on the front end.
Recommendations
Update WP Delicious WordPress plugin to version 1.10.8 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Delicious