WordPress Plugin Vulnerabilities
ShareThis Dashboard for Google Analytics < 2.5.2 - Reflected Cross-Site Scripting (XSS)
Description
The plugin does not sanitise or escape the 'ga_action' parameter in the stats view before outputting it back in an attribute when the plugin is connected to a Google Analytics account, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator
Proof of Concept
Plugin needs to be connected to Google Analytics account. https://example.com/wp-admin/admin.php?page=googleanalytics&ga_action=%22%3E%3Cimg+src%3Dx+onerror%3Dalert%28document.domain%29%3E
Affects Plugins
References
CVE
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
renniepak
Submitter
renniepak
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2021-08-02 (about 2 years ago)
Added
2021-08-02 (about 2 years ago)
Last Updated
2022-02-24 (about 1 years ago)