WordPress Plugin Vulnerabilities
SmokeSignal <= 1.2.6 - Authenticated Stored XSS
Description
Plugin description: "This plugin allows you to communicate with other registered users of you wordpress blog/website/portal easily inside admin interface."
Active installs (according to https://wordpress.org/plugins/smokesignal/): < 10
Messages aren't sanitized before they are displayed, so it's possible to inject <script> tags for example.
Low privileged accounts like subscribers can write message too.
Found by:
Paul Dannewitz
Other vulnerabilities I submitted to wpvulndb: https://wpvulndb.com/search?utf8=%E2%9C%93&text=Paul+Dannewitz
Affects Plugins
References
Classification
Type
XSS
OWASP top 10
CWE
Miscellaneous
Submitter
Paul Dannewitz
Submitter twitter
Verified
No
WPVDB ID
Timeline
Publicly Published
2017-09-02 (about 8 years ago)
Added
2017-09-19 (about 8 years ago)
Last Updated
2019-11-01 (about 6 years ago)