WordPress Plugin Vulnerabilities
WP Lead Plus X < 0.99 - Unauthenticated Stored Cross-Site Scripting (XSS)
Description
One of the features available to users who have paid for a license key for WP Lead Plus X is the ability to create and use "template" pages, which can be imported as a starting point when creating new pages. Although this feature is not visible if the plugin does not have a license key, it was still possible for an unauthenticated user to import a template containing malicious JavaScript. This was due to an admin_post action available to unprivileged visitors, c37_wpl_import_template
Proof of Concept
Affects Plugins
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Ramuel Gall (Wordfence)
Submitter
Ramuel Gall
Verified
No
WPVDB ID
Timeline
Publicly Published
2020-04-07 (about 5 years ago)
Added
2020-04-07 (about 5 years ago)
Last Updated
2021-01-19 (about 5 years ago)