CyberRota Analysis
AI-GeneratedThe Advanced Excerpt WordPress plugin prior to version 4.5 is vulnerable due to inadequate sanitization and escaping of a setting, potentially allowing administrators to introduce Stored Cross-Site Scripting (XSS) attacks. This vulnerability can lead to malicious scripts being executed in the context of any visitor to the affected site, posing a significant risk to user data and site integrity. WordPress site administrators, particularly those managing multisite environments, should prioritize updating this plugin to mitigate the risk.
Original NVD Description
The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outputting it on the front end of the site, which could allow administrators (including those without the unfiltered_html capability, such as on multisite) to perform Stored Cross-Site Scripting attacks that execute in the context of any visitor viewing affected pages.