CyberRota Analysis
AI-GeneratedThe VikWidgetsLoader WordPress plugin prior to version 1.12.0 is vulnerable due to improper sanitization of a block attribute, enabling users with Contributor roles to inject arbitrary JavaScript into posts. This flaw allows the injected scripts to execute in the browsers of all users, including administrators, potentially leading to session hijacking or other malicious actions. WordPress site administrators and security teams should prioritize this vulnerability to mitigate risks associated with unauthorized script execution.
Original NVD Description
The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that executes in the browser of any user viewing the affected post, including the administrator who reviews the pending submission.