Multiple XSS Issues in WP-Editor Plugin for WordPress
CVE-2016-10877
6.1MEDIUM
What is CVE-2016-10877?
The WP-Editor plugin prior to version 1.2.6.3 for WordPress has multiple vulnerabilities related to Cross-Site Scripting (XSS). These issues can be exploited by attackers to inject malicious scripts that execute in the context of an administrator's session. This vulnerability poses a risk to the security of WordPress sites using the plugin, potentially leading to unauthorized actions and data exposure. Users are encouraged to update to the latest version to mitigate these security concerns.