CyberRota Analysis
AI-GeneratedThe Comments plugin for WordPress versions prior to 7.6.60 is vulnerable due to improper escaping of user-supplied URLs, which can lead to Cross-Site Scripting (XSS) attacks. This flaw allows unauthenticated users to inject malicious scripts that execute in the browsers of anyone viewing the affected content, including administrators. WordPress site administrators and users of the Comments plugin should prioritize updating to the latest version to mitigate this security risk.
Original NVD Description
The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an HTML attribute, allowing unauthenticated users to store a Cross-Site Scripting payload that executes in the browser of any user, including administrators, who views the affected content.