Lucene search

K
wpvulndbWpvulndbWPVDB-ID:9D3B781A-4495-4578-AA92-8DBD6E8A33EC
HistoryOct 02, 2019 - 12:00 a.m.

Download Plugins and Themes from Dashboard <= 1.5.0 - Unauthenticated Stored XSS

2019-10-0200:00:00
wpscan.com
13

EPSS

0.001

Percentile

36.1%

NinTechNet discovered a multiple security issues within the Download Plugins and Themes from Dashboard WordPress plugin. The plugin’s setting update request did not check for authorisation, allowing an unauthenticated user to inject malicious JavaScript, which would be stored in the backend database. The vendor fixed the issue by checking the user’s capabilities, adding a Cross-Site Request Forgery (CSRF) nonce and encoding the affected paramater’s output.

EPSS

0.001

Percentile

36.1%

Related for WPVDB-ID:9D3B781A-4495-4578-AA92-8DBD6E8A33EC