The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/edit.php?post_type=forum (aka the Forum listing page) for all users. An administrator can exploit this at the wp-admin/post.php?action=edit URI.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://codex.bbpress.org/releases/ | vendor advisory |
https://wordpress.org/plugins/bbpress/#developers | third party advisory |
https://bbpress.org/ | vendor advisory |
https://www.youtube.com/watch?v=3rXP8CGTe08 | third party advisory exploit |