WordPress Plugin Vulnerabilities

WP SMS < 5.4.13 - Authenticated Stored Cross-Site Scripting

Description

The plugin does not sanitise the "wp_group_name" parameter before outputting it back in the "Groups" page, leading to an Authenticated Stored Cross-Site Scripting issue

(WPScanTeam): During the verification of the fixes with the vendor, other payloads and injection points were identified, reported and fixed

Proof of Concept

Add/edit a Group with the following name: <svg/onload=alert(/XSS/)>

(WPScanTeam): Another payload (noticed when working with the vendor on the fixes) 1')" style=animation-name:rotation onanimationstart=alert(/XSS/)//

Affects Plugins

Fixed in 5.4.13

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Muhammad Daffa
Submitter
Muhammad Daffa
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2021-07-26 (about 2 years ago)
Added
2021-07-26 (about 2 years ago)
Last Updated
2022-02-24 (about 2 years ago)

Other