Stored Cross-Site Scripting Vulnerability in MarqueeAddons Plugin for WordPress

Post Reply
Shane1145
Posts: 1836
Joined: Wed Sep 25, 2024 2:31 pm

Stored Cross-Site Scripting Vulnerability in MarqueeAddons Plugin for WordPress

Post by Shane1145 »

The MarqueeAddons plugin for WordPress exhibits a vulnerability that allows for Stored Cross-Site Scripting through its Testimonial Marquee widget. This flaw arises from inadequate input sanitization and output escaping on user-supplied attributes, enabling authenticated users with contributor-level access or higher to insert arbitrary scripts into pages. Consequently, these scripts execute when any user views an affected page, potentially compromising user data and website integrity.

https://securityvulnerability.io/vulner ... -2025-8199
Post Reply