Description
WordPress Sonaar Music Plugin 4.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the comment functionality. Attackers can submit JavaScript payloads in the comment parameter to wp-comments-post.php which are stored and executed in the browsers of users viewing the affected playlist pages.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
Furkan Karaarslan
References
www.exploit-db.com/exploits/51739 (ExploitDB-51739)
www.vulncheck.com/...ar-music-plugin-stored-xss-via-comments (VulnCheck Advisory: WordPress Sonaar Music Plugin 4.7 Stored XSS via Comments)