Description
It has been discovered that the ckeditor-wordcount-plugin plugin for CKEditor4 is susceptible to cross-site scripting when switching to the source code mode.
Recommendation
Update the ckeditor-wordcount-plugin package to the latest compatible version. Followings are version details:
- Affected version(s): <= 1.17.11
- Patched version(s): 1.17.12
References
Could your website be exposed too?
SmartScanner can check your website for ckeditor-wordcount-plugin vulnerable to Cross-site Scripting in Source Mode of Editor and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Jodit Editor vulnerable to cross-site scripting - CVE-2023-42399
- editor.md vulnerable to Cross-site Scripting - CVE-2023-29641
- Enhanced Image plugin for CKEditor is vulnerable to Cross-site scripting (XSS) - CVE-2018-9861
- Froala Editor Cross-site Scripting vulnerability - CVE-2023-41592


