What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nick Halsey List Custom Taxonomy Widget allows Stored XSS.This issue affects List Custom Taxonomy Widget: from n/a through 4.1.
Explanation of Vulnerability in Simple Terms
02Summary
List Custom Taxonomy Widget versions up to 4.1 contain a cross-site scripting (XSS) vulnerability in widget output. An authenticated user with high privileges can inject malicious scripts that execute in the browsers of site visitors who view pages containing the widget. The vulnerability requires user interaction and affects the integrity and confidentiality of visitor data.
What an attacker can do
03Attacker Capabilities
Inject malicious scripts that run in visitors' browsers when they view pages with the affected widget.
Potential impact on your site
04Site Impact
Visitors' browsers can be compromised; their session data, cookies, or credentials may be stolen by injected scripts.
Conditions required to exploit
05Prerequisites
Attacker must have high-level admin privileges and a visitor must view a page containing the vulnerable widget.
Key dates
06Disclosure timeline
April 24, 2024
CVE published
April 28, 2026
Record updated