THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-w93q-cq9w-58p7 (high) — SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed

[GHSA] GHSA-w93q-cq9w-58p7 (high) — SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed

medgithub_advisoriesPublished 2026-08-26

GHSA-w93q-cq9w-58p7 Severity: high CVE: CVE-2026-54606

SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed

Summary

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the SunEditor Embed plugin. Crafted iframe embed HTML followed by an external <script src=...> element bypasses the plugin’s sanitization logic. The plugin recreates and appends the attacke

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-w93q-cq9w-58p7