THREAT OPS › Threat News › [GHSA] GHSA-w93q-cq9w-58p7 (high) — SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed
[GHSA] GHSA-w93q-cq9w-58p7 (high) — SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed
GHSA-w93q-cq9w-58p7 Severity: high CVE: CVE-2026-54606
SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed
Summary
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the SunEditor Embed plugin. Crafted iframe embed HTML followed by an external <script src=...> element bypasses the plugin’s sanitization logic. The plugin recreates and appends the attacke
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-54606cve
Original source: https://github.com/advisories/GHSA-w93q-cq9w-58p7