WordPress Plugin Vulnerabilities

StreamCast < 2.1.1 - Contributor+ Stored Cross-Site Scripting

Description

The plugin does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode

Proof of Concept

Log in as contributor and add the following shortcode in a post [stream url='" onerror="alert(/XSS/)"']

Then view the post to trigger the XSS

Affects Plugins

Fixed in 2.1.1

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Michał Lipiński
Submitter website
Verified
Yes

Timeline

Publicly Published
2021-09-20 (about 2 years ago)
Added
2021-09-20 (about 2 years ago)
Last Updated
2022-04-08 (about 2 years ago)

Other