Description
ckeditor-wordcount-plugin is an open source WordCount Plugin for CKEditor. It has been discovered that the `ckeditor-wordcount-plugin` plugin for CKEditor4 is susceptible to cross-site scripting when switching to the source code mode. This issue has been addressed in version 1.17.12 of the `ckeditor-wordcount-plugin` plugin and users are advised to upgrade. There are no known workarounds for this vulnerability.
References (5)
Core 5
Core References
Vendor Advisory
https://typo3.org/security/advisory/typo3-core-sa-2023-004
Vendor Advisory x_refsource_confirm
https://github.com/w8tcha/CKEditor-WordCount-Plugin/security/advisories/GHSA-q9w4-w667-qqj4
Scores
CVSS v3
6.1
EPSS
0.0062
EPSS Percentile
70.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
ckeditor-wordcount-plugin_project/ckeditor-wordcount-plugin
< 1.17.12
npm/ckeditor-wordcount-plugin
0 - 1.17.12npm
Published
Jul 21, 2023
Tracked Since
Feb 18, 2026