WordPress Plugin Vulnerabilities

WP Mobile Detector <= 3.2 - Stored Cross-Site Scripting (XSS)

Description

The WP Mobile Detector plugin exposes the AJAX action ‘websitez_options’ to all registered users on line 78 of wp-mobile-detector/websitez-wp-mobile-detector.php. Providing specially crafted form values will result in a Persistent XSS attack on Mobile visitors.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Submitter
James Hooker
Submitter website
Submitter twitter
Verified
No

Timeline

Publicly Published
2015-06-25 (about 10 years ago)
Added
2015-06-25 (about 10 years ago)
Last Updated
2019-10-21 (about 6 years ago)

Other