CyberRota Analysis
AI-GeneratedThe CoolClock WordPress plugin prior to version 4.3.8 is vulnerable to cross-site scripting (XSS) due to improper escaping of a custom skin setting, enabling users with contributor-level access and above to inject malicious JavaScript. This could lead to unauthorized actions or data exposure when the content is viewed by others. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate potential security risks.
Original NVD Description
The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes when the content is viewed.