Custom Community 2.0 - 2.0.24 - Stored Cross-Site Scripting
highThe Custom Community theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘settings[custom_css]’ parameter in versions 2.0 through 2.0.24 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wil...
- CVSS:
- 8.3
- Affected:
- 2.0 – 2.0.25
- Fixed in:
- 2.0.25
- Disclosed:
- Mar 9, 2015