Easy Custom JS And CSS <= 1.1.2 - Reflected Cross-Site Scripting
medium
The Easy Custom JS And CSS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- CVSS:
- 6.1
- Affected:
- up to 1.1.2
- Fix:
- No patched version reported
- Disclosed:
- Oct 11, 2021
WordPress Easy Custom Js And Css Plugin [easy-custom-js-and-css] <= 1.1.2 (unfixed)
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Easy Custom Js And Css plugin (versions <= 1.1.2).
- Affected:
- up to 1.1.2
- Fix:
- No patched version reported
- Disclosed:
- Oct 11, 2021
WordPress Easy Custom Js And Css Plugin [easy-custom-js-and-css] <= 1.1.2 (unfixed)
unknown
The Easy Custom JS And CSS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- Affected:
- up to 1.1.2
- Fix:
- No patched version reported
- Disclosed:
- Oct 11, 2021
WordPress Easy Custom Js And Css Plugin [easy-custom-js-and-css] <= 1.1.2 (unfixed)
unknown
Most plugins (both free and premium) from the Avirtum author do not escape a page parameter before outputting it back in attributes, leading to Reflected Cross-Site Scripting issues.
The issues were reported to the vendor on August 4th, 2021
- Affected:
- up to 1.1.2
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database