cleantalk
Vulnerabilities and Security Researches

WP24 Domain Check, 4c4075de-c6e0-4130-8cad-a4ea5311f5ea

Application

WP24 Domain Check

Published on
-
Research Description
WP24 Domain Check [wp24-domain-check] < 1.6.3 WP24 Domain Check &lt; 1.6.3 - Authenticated Stored Cross-Site Scripting (XSS) The plugin version 1.6.2 and possibly below, was vulnerable to Stored Cross-Site Scripting (XSS) in the plugin&#039;s fieldnameDomain settings parameter. The form did require a valid CSRF nonce, limiting the exploitability of the vulnerability.
Affected versions
max 1.6.3.
Status
vulnerable