cleantalk
Vulnerabilities and Security Researches

Companion Auto Update, 4ed0f911f8fcd2b401511da7c4879e693fff1d89

Application

Companion Auto Update

Published on
Jun 01, 2017
Research Description
Companion Auto Update [companion-auto-update] < 2.9.4 WordPress Companion Auto Update plugin <=2.9.3 - Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) Vulnerabilities WordPress Companion Auto Update plugin Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) vulnerability. The CSRF occurs when you try to change the plugin’s settings. There's no nonce to validate the request. The XSS vulnerability appears for "Email address" input field, the output is not escaped. Update the plugin.
Affected versions
max 2.9.4.
Status
vulnerable