WordPress Plugin Vulnerabilities

Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite < 1.0.0 - CSRF to Stored XSS

Description

The plugin does not have CSRF checks in place when saving its settings, and do not sanitise or escape them before outputting them back in the page, leading to a stored Cross-Site Scripting issue via a CSRF attack

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Kenichiro Ito
Verified
No

Timeline

Publicly Published
2023-06-26 (about 2 years ago)
Added
2023-06-27 (about 2 years ago)
Last Updated
2023-06-27 (about 2 years ago)

Other