WordPress DeepDigital Theme Content Injection Vulnerability
Vulnerability
A content injection vulnerability has been identified in the WordPress DeepDigital theme, specifically in versions through 1.0.2. This vulnerability allows for improper neutralization of script-related HTML tags, leading to basic cross-site scripting (XSS) issues. Additionally, it enables arbitrary execution of shortcodes, which could be exploited to inject malicious content or phishing pages into the site's posts and pages.
Impact
Exploitation of this vulnerability could result in unauthorized content being injected into WordPress pages or posts, potentially including malicious or phishing-related material.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
