WordPress Plugin Vulnerabilities

NextScripts: Social Networks Auto-Poster < 3.4.18 - CSRF to Stored XSS

Description

The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to a Persistent XSS attack on the settings screen, due to a lack of sanitation of user input, and lack of Cross-Site Request Forgery token (nonce).

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Submitter
James Hooker
Submitter website
Submitter twitter
Verified
No

Timeline

Publicly Published
2015-05-25 (about 10 years ago)
Added
2015-05-26 (about 10 years ago)
Last Updated
2020-09-05 (about 5 years ago)

Other