WordPress Plugin Vulnerabilities

WP Reactions Lite < 1.3.6 - Authenticated Stored Cross Site Scripting

Description

The plugin does not properly sanitize inputs within wp-admin pages, allowing users with sufficient access to inject XSS payloads within /wp-admin/ pages.

Proof of Concept

Affects Plugins

Fixed in 1.3.6

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Shivam Rai
Submitter
Shivam Rai
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2021-09-28 (about 4 years ago)
Added
2021-09-28 (about 4 years ago)
Last Updated
2022-04-08 (about 3 years ago)

Other