CVE-2020-14063
TC Custom JavaScript <= 1.2.1 - Unauthenticated Stored Cross-Site Scripting
highImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
8.3
CVSS Score
8.3
CVSS Score
high
Severity
1.2.2
Patched in
1281d
Time to patch
Description
A stored Cross-Site Scripting (XSS) vulnerability in the TC Custom JavaScript plugin before 1.2.2 for WordPress allows unauthenticated remote attackers to inject arbitrary JavaScript via the tccj-content parameter. This is displayed in the page footer of every front-end page and executed in the browser of visitors.
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:LAttack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Low
Confidentiality
Low
Integrity
Low
Availability
Technical Details
Affected versions
<1.2.2PublishedJuly 21, 2020
Last updatedJanuary 22, 2024
Affected plugintc-custom-javascript
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.