WordPress Plugin Vulnerabilities

Sell Media < 2.4.2 - Unauthenticated Reflected Cross-Site Scripting (XSS)

Description

A Cross-site scripting (XSS) vulnerability in /inc/class-search.php in the Sell Media plugin v2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the keyword parameter (aka $search_term or the Search field).

Proof of Concept

Affects Plugins

Fixed in 2.4.2

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Metamorfosec
Verified
Yes

Timeline

Publicly Published
2020-08-14 (about 5 years ago)
Added
2020-08-14 (about 5 years ago)
Last Updated
2020-08-15 (about 5 years ago)

Other