WordPress MaxButtons Plugin 'wp-admin/admin.php' Cross Site Scripting Vulnerability
BID:70598
Info
WordPress MaxButtons Plugin 'wp-admin/admin.php' Cross Site Scripting Vulnerability
| Bugtraq ID: | 70598 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-7181 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 15 2014 12:00AM |
| Updated: | Oct 15 2014 12:00AM |
| Credit: | High-Tech Bridge Security Research |
| Vulnerable: |
WordPress MaxButtons plugin 1.26 |
| Not Vulnerable: |
WordPress MaxButtons plugin 1.26.1 |
Discussion
WordPress MaxButtons Plugin 'wp-admin/admin.php' Cross Site Scripting Vulnerability
The MaxButtons plugin for WordPress is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
MaxButtons 1.26.0 is vulnerable; other versions may also be affected.
The MaxButtons plugin for WordPress is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
MaxButtons 1.26.0 is vulnerable; other versions may also be affected.
References
WordPress MaxButtons Plugin 'wp-admin/admin.php' Cross Site Scripting Vulnerability
References:
References:
- MaxButtons Plugin Homepage (WordPress)
- WordPress HomePage (WordPress)
- Reflected Cross-Site Scripting (XSS) in MaxButtons WordPress Plugin (High-Tech Bridge Security Research Lab)