WordPress Plugin Vulnerabilities

Business Directory Plugin < 5.11.2 - Authenticated Stored Cross-Site Scripting

Description

The plugin suffered from lack of sanitisation in the label of the Form Fields, leading to Authenticated Stored Cross-Site Scripting issues across various pages of the plugin.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
0xB9
Submitter
0xB9
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2021-04-12 (about 4 years ago)
Added
2021-04-12 (about 4 years ago)
Last Updated
2021-04-14 (about 4 years ago)

Other