The Raygun4WP plugin 1.8.0 for WordPress is vulnerable to a reflected XSS in sendtesterror.php (backurl parameter).
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/MindscapeHQ/raygun4wordpress/issues/16 | third party advisory |
https://wpvulndb.com/vulnerabilities/8836 | |
https://github.com/MindscapeHQ/raygun4wordpress/pull/17 | third party advisory |
http://jgj212.blogspot.kr/2017/05/a-reflected-xss-vulnerability-in.html | third party advisory exploit |