The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.24 does not sanitise and escape logged requests before outputting them in the related admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting issue
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/b99dae3d-8230-4427-adc5-4ef9cbfb8ba1 | third party advisory exploit |
https://plugins.trac.wordpress.org/changeset/2650138 | third party advisory patch |