WordPress Plugin Vulnerabilities

WP Amour < 1.5.7 - Authenticated Stored Cross-Site Scripting (XSS)

Description

The plugin did not sanitise and escape its setting fields, leading to Stored Cross-Site Scripting issues. Furthermore, the lack of CSRF checks could also allow attackers to trigger the XSS via CSRF attacks against a logged in administrator

Proof of Concept

Affects Plugins

Fixed in 1.5.7

References

Classification

Type
XSS
CWE

Miscellaneous

Verified
Yes

Timeline

Publicly Published
2021-02-08 (about 5 years ago)
Added
2021-02-08 (about 5 years ago)
Last Updated
2021-02-08 (about 5 years ago)

Other