Stored Cross-Site Scripting in SKT Skill Bar Plugin for WordPress
CVE-2026-6972
6.4MEDIUM
What is CVE-2026-6972?
The SKT Skill Bar plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping on the chart_size attribute within the skillwrapper shortcode. This vulnerability allows authenticated users with Contributor-level access or higher to inject malicious web scripts into pages, which execute when an affected page is loaded by an unsuspecting visitor. The risk arises because the chart_size value is directly included in an inline <style> block, bypassing security measures designed to prevent such attacks.
Affected Version(s)
SKT Skill Bar 0 <= 2.6