WordPress Plugin Vulnerabilities

WP Custom Body Class <= 0.7.0 - CSRF to Stored XSS and Settings Update

Description

Lack of CSRF check and sanitisation when updating the plugin's settings could lead to unauthorised settings update as well as stored XSS issues

XSS fixed in 0.7.0. CSRF still there - vendor contacted
CSRF fixed in 0.7.1

Proof of Concept

Affects Plugins

Fixed in 0.7.1

References

Miscellaneous

Verified
Yes

Timeline

Publicly Published
2019-07-08 (about 6 years ago)
Added
2019-07-15 (about 6 years ago)
Last Updated
2019-07-16 (about 6 years ago)

Other