WordPress Plugin Vulnerabilities

WP Code Highlight.js < 0.6.3 - CSRF to Stored XSS

Description

Lack of CSRF checks could allow attackers to make a logged in admin create XSS payloads.

Proof of Concept

Affects Plugins

Fixed in 0.6.3

References

Classification

Miscellaneous

Original Researcher
jason0x90
Verified
No

Timeline

Publicly Published
2019-07-17 (about 6 years ago)
Added
2020-07-13 (about 5 years ago)
Last Updated
2020-07-16 (about 5 years ago)

Other