WordPress Plugin Vulnerabilities

Contact Form Check Tester <= 1.0.2 - Broken Access Control to Cross-Site Scripting (XSS)

Description

The plugin settings are visible to all registered users in the dashboard and are lacking any sanitisation. As a result, any registered user, such as subscriber, can leave an XSS payload in the plugin settings, which will be triggered by any user visiting them, and could allow for privilege escalation. The vendor decided to close the plugin.

Proof of Concept

Affects Plugins

References

Classification

Type
ACCESS CONTROLS
CWE
CVSS

Miscellaneous

Original Researcher
0xB9
Submitter
0xB9
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2021-04-10 (about 4 years ago)
Added
2021-04-10 (about 4 years ago)
Last Updated
2021-04-12 (about 4 years ago)

Other