cleantalk
Vulnerabilities and Security Researches

Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor, 25a554c8edab92a663999b7fff7239c6e4c47741

Published on
Jun 12, 2023
Research Description
Guest posting / Frontend Posting / Front Editor – WP Front User Submit [front-editor] < 3.8.0 Front User Submit | Front Editor <= 3.7.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting The Front User Submit | Front Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘formBuilderData’ parameter saved through the save_post_front_settings() function called via AJAX in versions up to, and including, 3.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 3.8.0.
Status
vulnerable