WordPress WP-RecentComments Plugin '/trunk/core.php' Cross Site Scripting Vulnerability
BID:49734
Info
WordPress WP-RecentComments Plugin '/trunk/core.php' Cross Site Scripting Vulnerability
| Bugtraq ID: | 49734 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-1068 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2011 12:00AM |
| Updated: | Feb 16 2012 05:50PM |
| Credit: | The vendor |
| Vulnerable: |
WordPress WP-RecentComments 2.0.6 |
| Not Vulnerable: |
WordPress WP-RecentComments 2.0.7 |
Discussion
WordPress WP-RecentComments Plugin '/trunk/core.php' Cross Site Scripting Vulnerability
The WP-RecentComments Plugin for WordPress is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary HTML and script code in a user's browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
WP-RecentComments plugin versions prior to 2.0.7 are vulnerable.
The WP-RecentComments Plugin for WordPress is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary HTML and script code in a user's browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
WP-RecentComments plugin versions prior to 2.0.7 are vulnerable.
Exploit / POC
WordPress WP-RecentComments Plugin '/trunk/core.php' Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
WordPress WP-RecentComments Plugin '/trunk/core.php' Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.
References
WordPress WP-RecentComments Plugin '/trunk/core.php' Cross Site Scripting Vulnerability
References:
References:
- WordPress Plugin Repository (WordPress)
- WordPress WP-RecentComments Plugin Product Page (WP-RecentComments)