CyberRota Analysis
AI-GeneratedThe SOGO Add Script to Individual Pages Header Footer WordPress plugin allows users with contributor-level access and above to inject unsanitized JavaScript into post headers and footers, posing a risk of cross-site scripting (XSS) attacks. This vulnerability can lead to unauthorized script execution in the browsers of administrators and visitors, potentially compromising site integrity and user data. WordPress site administrators and developers should prioritize this issue to mitigate the risk of exploitation.
Original NVD Description
The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from its post metabox, and does not restrict them to users with the unfiltered_html capability, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any administrator who reviews the post and of any visitor once the post is published.