WordPress Plugin Vulnerabilities

WP Lead Plus X < 0.99 - Unauthenticated Stored Cross-Site Scripting (XSS)

Description

One of the features available to users who have paid for a license key for WP Lead Plus X is the ability to create and use "template" pages, which can be imported as a starting point when creating new pages. Although this feature is not visible if the plugin does not have a license key, it was still possible for an unauthenticated user to import a template containing malicious JavaScript. This was due to an admin_post action available to unprivileged visitors, c37_wpl_import_template

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Ramuel Gall (Wordfence)
Submitter
Ramuel Gall
Verified
No

Timeline

Publicly Published
2020-04-07 (about 5 years ago)
Added
2020-04-07 (about 5 years ago)
Last Updated
2021-01-19 (about 5 years ago)

Other