CyberRota Analysis
AI-GeneratedThe CoolClock WordPress plugin versions prior to 4.3.8 are vulnerable to cross-site scripting (XSS) due to improper escaping of a skin setting in HTML attributes. This flaw allows users with contributor-level access and higher to inject malicious scripts that execute when the content is viewed, potentially compromising site integrity and user data. WordPress site administrators, particularly those using the affected plugin, should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed.