Cross-site scripting (XSS) vulnerability in nextend-facebook-settings.php in the Nextend Facebook Connect plugin before 1.5.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the fb_login_button parameter in a newfb_update_options action.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://osvdb.org/show/osvdb/115231 | vdb entry |
http://security.szurek.pl/nextend-facebook-connect-1459-xss.html | exploit |
https://wordpress.org/plugins/nextend-facebook-connect/changelog/ | vendor advisory |
http://www.exploit-db.com/exploits/35439 | exploit |