WordPress Plugin Vulnerabilities

3D FlipBook < 1.12.1 - Subscriber+ Stored Cross-Site Scripting

Description

The plugin does not have authorisation and CSRF checks when updating its settings, and does not have any sanitisation/escaping, allowing any authenticated users, such as subscriber to put Cross-Site Scripting payloads in all pages with a 3d flipbook.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Krzysztof Zając
Submitter
Krzysztof Zając
Submitter website
Verified
Yes

Timeline

Publicly Published
2022-02-28 (about 3 years ago)
Added
2022-02-28 (about 3 years ago)
Last Updated
2022-04-17 (about 3 years ago)

Other