WordPress Plugin Vulnerabilities

Loan Comparison < 1.5.3 - Reflected XSS via shortcode

Description

The plugin does not validate and escape some of its query parameters before outputting them back in a page/post via an embedded shortcode, which could allow an attacker to inject javascript into into the site via a crafted URL.

Proof of Concept

Affects Plugins

Fixed in 1.5.3

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Harald Eilertsen
Submitter
WPScan
Submitter website
Verified
Yes

Timeline

Publicly Published
2023-01-25 (about 2 years ago)
Added
2023-01-25 (about 2 years ago)
Last Updated
2023-01-25 (about 2 years ago)

Other