The Blog2Social plugin before 5.9.0 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the b2s_id parameter. The component is: views/b2s/post.calendar.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://wordpress.org/plugins/blog2social/#developers | third party advisory product |
https://plugins.trac.wordpress.org/changeset/2186043 | third party advisory patch |
https://plugins.trac.wordpress.org/log/blog2social/ | third party advisory |
https://wpvulndb.com/vulnerabilities/9948 | third party advisory |