WordPress Plugin Vulnerabilities

MonsterInsights < 8.9.1 - Stored Cross-Site Scripting via Google Analytics

Description

The plugin does not sanitize or escape page titles in the top posts/pages section, allowing an unauthenticated attacker to inject arbitrary web scripts into the titles by spoofing requests to google analytics.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Grzegorz Niedziela
Submitter
Grzegorz Niedziela
Verified
Yes

Timeline

Publicly Published
2022-12-23 (about 3 years ago)
Added
2022-12-26 (about 3 years ago)
Last Updated
2022-12-26 (about 3 years ago)

Other