WordPress Plugin Vulnerabilities

PowerPress Podcasting < 6.0.5 - Authenticated Cross-Site Scripting (XSS)

Description

By exploiting a Cross-site scripting vulnerability the attacker can hijack a logged in user’s session by stealing cookies. This means that the malicious hacker can change the logged in user’s password and invalidate the session of the victim while the hacker maintains access.

Proof of Concept

Affects Plugins

Fixed in 6.0.5

References

Classification

Type
XSS
CWE

Miscellaneous

Submitter
ethicalhack3r
Submitter twitter
Verified
No

Timeline

Publicly Published
2015-09-14 (about 10 years ago)
Added
2015-10-27 (about 10 years ago)
Last Updated
2020-10-23 (about 5 years ago)

Other