The answer is in your question.
I try this when login as admin and editor.
The roles have the unfiltered_html
capability that allows them to put whatever HTML they choose, including <script>
tags, where ever they choose.
Is is a security risk? Only if you give folks you don’t trust admin and/or editor roles. Or someone gains access to your an admin/editor account. Or there’s another security hole somewhere in the core that allows privilege escalation from a lower to higher user level (unlikely).
By itself, it’s not a security risk. Admin and editors need to be able to do things to actually manage the site.
Related Posts:
- comment_post_ID 0 (cannot remove from dashboard)
- Enable Submit Comment Without Page Reload (Using Ajax)?
- Comment Reply javascript
- Why do I get accidental comments without (the required) email address?
- Comment form validation
- How to Block Access to Standard Login Flow and Comment Flow
- Strategies for coping with hyperagressive spambots?
- Sanitizing comments or escaping comment_text()
- wp_insert_comment and security
- Is WordPress vulnerable to “comment posting forgery”?
- Display the number of unseen comments on a page since the user last visit
- Using defer or async JavaScript attributes prevents pingbacks and trackbacks from being sent
- reCaptcha doesnt appear in comment (manual or plugin)
- WordPress scruity issue – Totally disable all comments by CSS — secure enough?
- How are readers authenticated for leaving comments?
- Remove Javascript generated by Comments
- Comment form in wordpress theme returns a javascript alert
- WordPress Commenting System User access and Security
- js solution to… Commentor can only post one comment BUT can reply to their comment tree unlimited [duplicate]
- Comments – Ensure the correct field is highlighted for nested replies
- How do I comment out a block of tags in XML?
- SecurityError: Blocked a frame with origin from accessing a cross-origin frame
- R: Comment out block of code
- Why do I get comment spam even with Akismet and Captcha?
- What tools are available for managing/writing to WordPress? [closed]
- How to rearrange fields in comment_form()
- setting comments off as default for pages and custom post types?
- Is it possible to pull comments from facebook into your blog?
- Filtering the Admin Comments List to Show Only Comments from the Current User?
- Non-threaded comment replies with link to original comment
- Approve comment hook?
- Commenting in user profile page?
- How to change “You must be logged in to post a comment.”
- Disable comments on all posts/pages
- How do I delete all comments from a specific old blog post?
- Removing the “Website” Field from Comments and Replies?
- Stop WordPress redirecting comment-page-1 to the post page?
- Importing old Disqus comments into WordPress
- How to add a class to the comment submit button?
- How to wrap submit button of comment form with div
- How to enable comments for pending and draft posts?
- Using WordPress’ WYSIWYG for comments
- What for is the table “wp_commentmeta” exactly?
- Getting Post Comments for post ID using WP_Query() and a Custom Loop?
- Add option to disable comments on a per posts basis?
- Resetting comment count
- When importing – failed to import: Invalid post type feedback
- How to change the email notification recipient (user) for new comments?
- Redirect user to a custom url after submitting the comment
- Paginate result set from $wpdb->get_results()
- Change Comment Author Display Name
- Would switching to InnoDB from MyISAM improve performance of comments table?
- Custom comment type based on thread level
- How to add internal, revision comments to page updates
- How to load and show comments with AJAX instead of pagination?
- Linking to Page Showing Only Comments Without Parent Post
- How do we remove the H3 tag for the reply-title I.D
- Comments not appearing at all
- comments reply script not working
- How to display comment form error messages in the same page
- 3 moderators to approve comment
- How to deal with small scale comment spam on small commercial sites? [closed]
- What should I do to make generated avatars different for anonymous comments?
- A plugin where users can comment with Facebook or Twitter or OpenID [closed]
- Check If comment author is registered
- Comments screen in backend, how to disable email address of commenter for non admins
- Add comments from the admin panel?
- How can I limit the number of comments per registered user per day?
- One comment per user per post but be able to reply to existing comments
- How to use a custom comments template
- Comment visibility
- What’s the easiest way to close comments on media/attachments?
- Reverse comment pagination numbers
- Get comments for more than one post
- How can I add comments to a page?
- How to remove comment spam in WordPress
- Post Comments using WP REST API v2 in WordPress
- show number of open comments on custom dashboard
- Show content only if member left a comment
- Add placeholder attribute to comment form fields
- How is comment spam received without a comments form?
- Does a reply to a wordpress comment notify the author of the comment?
- What are the current recommended best-practices for comments.php?
- human_time_diff() returns “48 years ago” for all comments
- How do I set up real anonymous posting in bbpress forums? [closed]
- Comment Count for each Comment Author
- Link name in comments to Author page? Comment Author Meta in Comments?
- How do I turn off wordpress comments ability to capture a users ip address?
- Showing comments only to same custom user role
- Parent comment’s author name
- Success message in comment form
- get_comments_number of depth-1 (Level 1) (1 post)
- Show comments from multiple post IDs in comment template
- Running a function on comment status change
- How to allow the reply link to remain on the comment form after I have reached my 10 nested comment limit?
- How can I control the comment counts filtering my CPT replies?
- Hook to edit an column on comments screen?
- Allowing more elements in comments via functions.php
- Set post comments open function
- Comment Author Name In Reply Form