Jump to content
YOUR-AD-HERE
HOSTING
TOOLS
992Proxy

Locked The "Add Link to Facebook" plugin through 2.3 for WordPress has XSS


dEEpEst

Recommended Posts

[hide-thanks]

well ,sir ,i just found a stored-xss bug here.

The report link to the wordpress-form is missing, because the manager do not wish to put the public in danger ,i'll just write some details here.

When i login into the wordpress panel, assume i have a low privilege role like a editor user.

 

This is the hidden content, please

 

 

[ATTACH=json]n111952[/ATTACH]

 

because the admin user has turned on the option of the wp-plugin add-link-to-facebook, a normal user like me can also use it.

I can write something in the profile page. By the way, i'm the user "test" now:

At the profile page:

 

This is the hidden content, please

 

but when i pentest the parameter in this plugin, i found when i write something into this point, it does not filter well:

 

Weak post parameter:

 

This is the hidden content, please
[/hide-thanks]
Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.