A stored Cross-Site Scripting (XSS) vulnerability in the TC Custom JavaScript plugin before 1.2.2 for WordPress allows unauthenticated remote attackers to inject arbitrary JavaScript via the tccj-content parameter. This is displayed in the page footer of every front-end page and executed in the browser of visitors.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-07-21T17:12:21

Updated: 2020-07-21T17:12:21

Reserved: 2020-06-14T00:00:00


Link: CVE-2020-14063

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-07-21T18:15:19.787

Modified: 2020-07-23T17:19:23.510


Link: CVE-2020-14063

JSON object: View

cve-icon Redhat Information

No data.

CWE