Impact
The Custom Logo plugin for WordPress is vulnerable to stored cross‑site scripting due to insufficient input sanitization and output escaping in the Logo Path setting. Administrators can embed arbitrary scripts that persist in the plugin configuration and are executed whenever a page using the logo is rendered, allowing a malicious user to hijack sessions, deface content, or run client‑side attacks on any visitor.
Affected Systems
WordPress installations running the Custom Logo plugin up to version 2.2, namely multisite deployments that have unfiltered_html disabled. The issue impacts the vendor tgrk’s Custom Logo plugin when these contextual conditions are met.
Risk and Exploitability
With a CVSS base score of 4.4 the flaw is classified as moderate severity. The EPSS indicates an exploitation probability of less than 1%, and it is not listed in the CISA KEV catalog. Exploitation requires an authenticated attacker with administrator privileges on a multisite WordPress site that has unfiltered_html turned off; once logged in, the attacker can inject JavaScript that will execute for all users viewing any affected page.
OpenCVE Enrichment