WordPress Plugin Vulnerabilities

iLive <= 1.0.4 - Stored Cross-Site Scripting (XSS)

Description

Info:
Weak security measures like bad textarea data filtering has been discovered in the 'iLive - Intelligent WordPress Live Chat Support Plugin'. Current version of this premium WordPress plugin is 1.0.4.

Demo Website:
https://codecanyon.net/item/ilive-wordpress-live-chat-support-plugin/20496563
Frontend: http://www.ilive.wpapplab.com/
Backend: http://www.ilive.wpapplab.com/wp-admin/
Login / Password (operator1): operator1 / Operator_1
Login / Password (operator2): operator2 / Operator_2
Login / Password (operator3): operator3 / Operator_3

Edit (WPScanTeam):
June 25th - Sent to Envato & they replied that they are investigating the issue.
No news since then (and plugin has not been updated since 2017).

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
m0ze
Submitter
m0ze
Submitter twitter
Verified
No

Timeline

Publicly Published
2019-06-25 (about 6 years ago)
Added
2019-07-09 (about 6 years ago)
Last Updated
2021-01-19 (about 5 years ago)

Other