A stored Cross-Site Scripting (XSS) vulnerability in the TC Custom JavaScript plugin before 1.2.2 for WordPress allows unauthenticated remote attackers to inject arbitrary JavaScript via the tccj-content parameter. This is displayed in the page footer of every front-end page and executed in the browser of visitors.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-07-21T17:12:21

Updated: 2024-08-04T12:32:14.681Z

Reserved: 2020-06-14T00:00:00

Link: CVE-2020-14063

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-07-21T18:15:19.787

Modified: 2020-07-23T17:19:23.510

Link: CVE-2020-14063

cve-icon Redhat

No data.