QID 150526
Date Published: 2022-06-16
QID 150526: WordPress WP Maintenance Plugin: Stored Cross-Site Scripting Vulnerability (CVE-2021-36828)
The WP Maintenance plugin allows you to put your website on the waiting time for you to do maintenance or launch your website.
The plugin does not sanitise and escape multiple of its settings, which could allow high privileged users such as admin to perform Cross-Site Scripting attack when the unfiltered_html is disallowed.
Affected Versions:
WordPress WP Maintenance Plugin before 6.0.6.
QID Detection Logic:
This QID sends a HTTP GET request and checks for vulnerable version of WordPress plugin running on the target application.
Successful exploitation could allow an attacker to execute arbitrary JavaScript code in the context of the interface or allow the attacker to access sensitive, browser-based information.
Solution
Customers are advised to upgrade to WP Maintenance 6.0.6 or later version to remediate this vulnerability. For more information regarding this vulnerability please refer WPScan Security Advisory
Vendor References
CVEs related to QID 150526
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WPScan |
|
||
| WordPress |
|