WordPress Plugin Vulnerabilities

Themify - Post Type Builder Search Addon < 1.4.0 - Reflected Cross-Site Scripting

Description

The plugin does not properly escape the current page URL before reusing it in a HTML attribute, leading to a reflected cross site scripting vulnerability.

Proof of Concept

On a page or post with a search form, add the following url query parameter: ?%22%3E%3Cscript%3Ealert(1)%3C/script%3E

Affects Plugins

Fixed in 1.4.0

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Kevin Barbón García, David Álvarez Robles, Francisco Díaz-Pache Alonso & Sergio Corral Cristo
Submitter
Kevin Barbón García
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2022-04-12 (about 1 years ago)
Added
2022-04-12 (about 1 years ago)
Last Updated
2022-04-13 (about 1 years ago)

Other