WordPress Plugin Vulnerabilities

ShareThis Dashboard for Google Analytics < 2.5.2 - Reflected Cross-Site Scripting (XSS)

Description

The plugin does not sanitise or escape the 'ga_action' parameter in the stats view before outputting it back in an attribute when the plugin is connected to a Google Analytics account, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

Proof of Concept

Plugin needs to be connected to Google Analytics account.

https://example.com/wp-admin/admin.php?page=googleanalytics&ga_action=%22%3E%3Cimg+src%3Dx+onerror%3Dalert%28document.domain%29%3E

Affects Plugins

Fixed in 2.5.2

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
renniepak
Submitter
renniepak
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2021-08-02 (about 2 years ago)
Added
2021-08-02 (about 2 years ago)
Last Updated
2022-02-24 (about 2 years ago)

Other