Description
Yoast Duplicate-Post WordPress Plugin 3.2.3 contains a persistent cross-site scripting vulnerability in plugin settings parameters. Attackers can inject malicious scripts into title prefix, suffix, menu order, and blacklist fields to execute arbitrary JavaScript in admin interfaces.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
0.3 (semver)
Credits
Unk9vvN
References
www.exploit-db.com/exploits/47424 (ExploitDB-47424)
duplicate-post.lopo.it/ (Duplicate Post Plugin Vendor Homepage)
wordpress.org/plugins/duplicate-post/ (WordPress Duplicate Post Plugin Repository)
www.vulncheck.com/...te-post-persistent-cross-site-scripting (VulnCheck Advisory: Duplicate-Post 3.2.3 - Persistent Cross-Site Scripting)
www.wordfence.com/...cated-admin-stored-cross-site-scripting