WordPress Plugin Vulnerabilities

Verse-O-Matic <= 4.1.1 - CSRF to Stored XSS

Description

The plugin does not have any CSRF checks in place, allowing attackers to make logged in administrators do unwanted actions, such as add/edit/delete arbitrary verses and change the settings. Due to the lack of sanitisation in the settings and verses, this could also lead to Stored Cross-Site Scripting issues

Proof of Concept

Affects Plugins

No known fix

References

Classification

Miscellaneous

Original Researcher
Ajay Sandipan Thorbole
Submitter
Ajay Sandipan Thorbole
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2021-07-19 (about 4 years ago)
Added
2021-07-19 (about 4 years ago)
Last Updated
2021-08-10 (about 4 years ago)

Other