WordPress Plugin Vulnerabilities

SmokeSignal <= 1.2.6 - Authenticated Stored XSS

Description

Plugin description: "This plugin allows you to communicate with other registered users of you wordpress blog/website/portal easily inside admin interface."
Active installs (according to https://wordpress.org/plugins/smokesignal/): < 10

Messages aren't sanitized before they are displayed, so it's possible to inject <script> tags for example.

Low privileged accounts like subscribers can write message too.

Found by:

Paul Dannewitz

Other vulnerabilities I submitted to wpvulndb: https://wpvulndb.com/search?utf8=%E2%9C%93&text=Paul+Dannewitz

Affects Plugins

Fixed in 1.2.7

References

Classification

Type
XSS
CWE

Miscellaneous

Submitter
Paul Dannewitz
Submitter twitter
Verified
No

Timeline

Publicly Published
2017-09-02 (about 8 years ago)
Added
2017-09-19 (about 8 years ago)
Last Updated
2019-11-01 (about 6 years ago)

Other