The answer is in your question.
I try this when login as admin and editor.
The roles have the unfiltered_html
capability that allows them to put whatever HTML they choose, including <script>
tags, where ever they choose.
Is is a security risk? Only if you give folks you don’t trust admin and/or editor roles. Or someone gains access to your an admin/editor account. Or there’s another security hole somewhere in the core that allows privilege escalation from a lower to higher user level (unlikely).
By itself, it’s not a security risk. Admin and editors need to be able to do things to actually manage the site.
Related Posts:
- comment_post_ID 0 (cannot remove from dashboard)
- Enable Submit Comment Without Page Reload (Using Ajax)?
- Comment Reply javascript
- Why do I get accidental comments without (the required) email address?
- Comment form validation
- How to Block Access to Standard Login Flow and Comment Flow
- Strategies for coping with hyperagressive spambots?
- Sanitizing comments or escaping comment_text()
- wp_insert_comment and security
- Is WordPress vulnerable to “comment posting forgery”?
- Display the number of unseen comments on a page since the user last visit
- Using defer or async JavaScript attributes prevents pingbacks and trackbacks from being sent
- reCaptcha doesnt appear in comment (manual or plugin)
- WordPress scruity issue – Totally disable all comments by CSS — secure enough?
- How are readers authenticated for leaving comments?
- Remove Javascript generated by Comments
- Comment form in wordpress theme returns a javascript alert
- WordPress Commenting System User access and Security
- js solution to… Commentor can only post one comment BUT can reply to their comment tree unlimited [duplicate]
- Comments – Ensure the correct field is highlighted for nested replies
- Is it possible to pull comments from facebook into your blog?
- How to deal with small scale comment spam on small commercial sites? [closed]
- Add placeholder attribute to comment form fields
- human_time_diff() returns “48 years ago” for all comments
- Allow anonymous comments, but prevent spam [closed]
- Where to remove from comment’s feed?
- Why are default comments deprecated?
- Comments Reply Form
- Delete all user comments
- Why do I get email notifications about comments that WordPress has already determined are spam?
- “Leave a comment” link even when you can’t
- How to check if commenter is the_author?
- How to save new comment as custom comment type?
- How to remove the “on” string before recent comments link?
- Whats the safest way to output custom JavaScript and Css code entered by the admin in the Theme Settings?
- WordPress unresponsive after calling wp_update_comment()
- edit comments capability for authors
- Publish a message on facebook after having posted a comment
- How can I edit the Twenty Ten Theme to remove the comments box when a page uses a specific template?
- Highlight Author Comments issues
- Nonces, AJAX, script variables & security in WordPress
- Users with custom roles can’t read each other’s comments
- How can I fix wp_insert_comment failure when ‘comment_content” includes slanted apostrophe in Excel csv source data
- Author can only see own post comment and can moderate
- highlight “starred” comments by admin
- How can I edit comment notification email content?
- Filter In Reply comments from WordPress Admin Panel
- How can I hide the IP of registered commentators?
- How to configure WordPress + plugins to support these commenting features
- Comments vs. Pingbacks next page issue
- How to automatically evaluate comment content without user seeing the delay?
- Comments invisible after moving WordPress to new server, while commenting still works
- Allow the comment author to delete their own comments
- css hide all the comment reply links except the lowest nested comments
- Spammers attacking my WordPress Site – Removing URL field from core? [closed]
- Prioritizing the wordpress comments
- Comments from vbulletin topic [closed]
- wp.getComments is returning nill, when i called from my iphone app [closed]
- How to override wp_insert_comment()
- Can I have Comments open to specific users only?
- How to edit the text below “Leave a Reply”
- Commenting system for WordPress
- Commentlist: bypostauthor problem with children list
- Comments does not work?
- How do I disable the discussion notification emails to us when a comment is “approved” and when an adiministrator replies?
- Review count per product
- Moving post’s content to post’s comments section
- comment_notes_before not working
- why can’t I retrieve the comment ID?
- get_comment_link without pagination base in the returned URL?
- Comments on future posts
- Copy and Paste Password for Comments
- Returning error upon comment being flagged as spam
- is it possible to have the full code instead in the comments.php page
- How do i remove approved spam comments by date?
- How to Trigger comment_form_after action if comment_form() not used
- Insert ads between comments
- get_query_var(‘paged’) for WP_Comment_Query always return 1 when using paginate_comments_links()
- How to only show current user’s comments and comments on current user’s posts in wp admin
- How to make author comment name to “Editorial Staff” no matter which ever author is replying to comments from his/her account?
- Changing the Comment Fields using Filter (without success)
- How to show username in reply to comment?
- Comments pagination: reverse JUST the links texts (1-2-3 to 3-2-1), not comments order
- Display date and time into post edit comments section
- Disallowed Tag Present in AMP WordPress ()
- Subcriber getting multiiple notifications for new comments
- Comments/Discussion Not enabled on newly created posts/pages
- Fire Social Annex Code on Comment Approval
- How can I enable commenting from mobile view?
- Let user delete comment on front end only
- How to force users to nest their comments
- jQuery to Create Button to Show/Hide WordPress Comments and to Hide Comments by Default
- Comment form – different title if no comment yet
- WordPress Comments jQuery Doesn’t submit
- Insert comment and still use moderation
- Loop not displaying comments_popup_link
- Display of comment_date within get_comments?
- How to batch convert comments to posts?
- I need help about wordpress of members section
- Add ACF Quick Edit Columns on Comments