cleantalk
Vulnerabilities and Security Researches

WP Crontrol, ee606200d06d026e615be1bbc222571330834d0d

Application

WP Crontrol

Published on
Aug 21, 2015
Research Description
WP Crontrol [wp-crontrol] < 1.3 WordPress Crontrol Plugin <= 1.2.3 - Cross Site Scripting (XSS) Because of this vulnerability, authenticated administrators can store HTML and JS code. Vulnerable parameters: "id[hookname]", "id[sig]", "id[next_run]", "id[args][code]". Update the plugin.
Affected versions
Min -, max 1.3.
Status
vulnerable