WordPress Plugin Vulnerabilities

Titan Framework <= 1.12.1 - Reflected Cross-Site Scripting (XSS)

Description

The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting issues

Edit (WPScanTeam):
- The original report mentioned the issue in the awesome-support plugin 6.0.1, however we scanned to WordPress plugins repository for such library being used and 49 plugins were found to be affected.
- The titan-framework has been permanently closed as no longer updated and maintained
- The full report, including all the affected plugins, was shared with WP plugins team on March 28th, 2021 and they gave vendors 3 months to find a replacement

Proof of Concept

Affects Plugins

No known fix
No known fix
No known fix
Fixed in 6.0.11
No known fix
No known fix
No known fix
No known fix
No known fix
No known fix
No known fix
Fixed in 1.5.0
No known fix
Fixed in 2.8.2.3
No known fix
No known fix
Fixed in 2.2.2
No known fix
No known fix
Fixed in 2.1.0
Fixed in 1.6.1
No known fix
Fixed in 2.4.0

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
iohex
Submitter
iohex
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2021-08-09 (about 4 years ago)
Added
2021-08-09 (about 4 years ago)
Last Updated
2023-01-24 (about 2 years ago)

Other