WordPress Plugin Vulnerabilities

Awesome Support < 6.0.0 - Stored XSS via Ticket Title

Description

The lack of sanitisation in the post_title of a ticket could allow users with the Support Supervisor capability to create tickets containing XSS payloads.

The risk is relatively low, as CSRF checks are in place and the affected role is close to an admin one. Using the DISALLOW_UNFILTERED_HTML
constant does not mitigate the attack.

January 10th, 2020 - WP Plugins Team Notified

Affects Plugins

Fixed in 6.0.0

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
0xPablito
Verified
Yes

Timeline

Publicly Published
2020-01-06 (about 6 years ago)
Added
2020-01-10 (about 6 years ago)
Last Updated
2020-09-22 (about 5 years ago)

Other