Executive brief
The CKEditor WordCount Plugin is a text analysis tool for CKEditor 4 that counts words in documents. When an editor switches to the HTML source code view, the plugin fails to properly sanitize user input, allowing attackers to inject and execute malicious JavaScript. This could enable account takeover, session hijacking, or defacement of page content depending on the editor's privilege level.
Technical details
This is a cross-site scripting (CWE-79) vulnerability in the CKEditor WordCount Plugin caused by insufficient input sanitization when rendering content in source mode. The vulnerability is exploitable over the network with no authentication required for frontend-exposed editors, though backend exploitation typically requires a valid user account. An attacker can craft malicious HTML containing JavaScript that will execute in the editor's context when a user switches to source mode. The vulnerability affects all versions up to and including 1.17.11; version 1.17.12 and later patch the issue by properly escaping/sanitizing input.
Affected products
- w8tcha ckeditor-wordcount-plugin <=1.17.11
Timeline
- 2023-07-10: disclosed: Security advisory GHSA-q9w4-w667-qqj4 published
- 2023-07-10: patched: Version 1.17.12 released with fix