WordPress Plugin Vulnerabilities
iLive <= 1.0.4 - Stored Cross-Site Scripting (XSS)
Description
Info:
Weak security measures like bad textarea data filtering has been discovered in the 'iLive - Intelligent WordPress Live Chat Support Plugin'. Current version of this premium WordPress plugin is 1.0.4.
Demo Website:
https://codecanyon.net/item/ilive-wordpress-live-chat-support-plugin/20496563
Frontend: http://www.ilive.wpapplab.com/
Backend: http://www.ilive.wpapplab.com/wp-admin/
Login / Password (operator1): operator1 / Operator_1
Login / Password (operator2): operator2 / Operator_2
Login / Password (operator3): operator3 / Operator_3
Edit (WPScanTeam):
June 25th - Sent to Envato & they replied that they are investigating the issue.
No news since then (and plugin has not been updated since 2017).
Proof of Concept
Affects Plugins
References
Classification
Type
XSS
OWASP top 10
CWE
Miscellaneous
Original Researcher
m0ze
Submitter
m0ze
Submitter twitter
Verified
No
WPVDB ID
Timeline
Publicly Published
2019-06-25 (about 6 years ago)
Added
2019-07-09 (about 6 years ago)
Last Updated
2021-01-19 (about 5 years ago)