The Random Banner WordPress plugin is vulnerable to...
Moderate severity
Unreviewed
Published
Jan 19, 2022
to the GitHub Advisory Database
•
Updated Jun 27, 2023
Description
Published by the National Vulnerability Database
Jan 18, 2022
Published to the GitHub Advisory Database
Jan 19, 2022
Last updated
Jun 27, 2023
The Random Banner WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the category parameter found in the ~/include/models/model.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 4.1.4. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.
References