Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor, 25a554c8edab92a663999b7fff7239c6e4c47741
- CVE, Research URL
- Home page URL
- Application
-
Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor
- Published on
- Jun 12, 2023
- Research Description
- Guest posting / Frontend Posting / Front Editor – WP Front User Submit [front-editor] < 3.8.0 Front User Submit | Front Editor <= 3.7.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting The Front User Submit | Front Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘formBuilderData’ parameter saved through the save_post_front_settings() function called via AJAX in versions up to, and including, 3.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 3.8.0.
- Status
-
vulnerable