WP Blockade
- <= 0.9.14
A reflected cross-site scripting vulnerability has been identified in the WP Blockade plugin for WordPress, affecting all versions through 0.9.14. The issue arises from inadequate input sanitization and output escaping in the render_shortcode_preview() function. This function processes user input from the 'shortcode' parameter without proper sanitization, allowing malicious scripts to be injected and executed on the page. The vulnerability requires the user to be logged in with at least a Subscriber-level account.
Exploitation of this vulnerability allows authenticated users with Subscriber-level access to inject and execute arbitrary JavaScript in the context of the user viewing the page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.