Description
Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access can craft a shortcode attribute that injects an event handler executing in a viewer's browser.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
Scott Moore - VulnCheck
References
wordpress.org/plugins/simple-link-directory/ (WordPress Plugin Repository)
www.vulncheck.com/...ored-xss-via-embed-shortcode-attributes (VulnCheck Advisory: Simple Link Directory through 9.0.4 Stored XSS via Embed Shortcode Attributes)