Medium severity6.1NVD Advisory· Published Jul 21, 2020· Updated Jun 17, 2026
CVE-2020-14063
CVE-2020-14063
Description
A stored Cross-Site Scripting (XSS) vulnerability in the TC Custom JavaScript plugin before 1.2.2 for WordPress allows unauthenticated remote attackers to inject arbitrary JavaScript via the tccj-content parameter. This is displayed in the page footer of every front-end page and executed in the browser of visitors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:tc_custom_javascript_project:tc_custom_javascript:*:*:*:*:*:wordpress:*:*Range: <1.2.2
- WordPress/Custom JavaScript plugindescription
- Range: <1.2.2
Patches
Vulnerability mechanics
References
2- www.wordfence.com/blog/2020/07/high-severity-vulnerability-patched-in-tc-custom-javascript/nvdExploitThird Party Advisory
- wordpress.org/plugins/tc-custom-javascript/nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.