cleantalk
Vulnerabilities and Security Researches

Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor, 6af0f76dff7fd5061b09f63c8144653654028249

Published on
Jun 27, 2023
Research Description
Guest posting / Frontend Posting / Front Editor – WP Front User Submit [front-editor] < 3.8.5 Front User Submit | Front Editor <= 3.8.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting The Front User Submit | Front Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via field labels in versions up to, and including, 3.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 3.8.5.
Status
vulnerable