vendor:
WP Symposium Pro Social Network plugin
by:
Rahul Pratap Singh
8,8
CVSS
HIGH
XSS and CSRF
79 (XSS) and 352 (CSRF)
CWE
Product Name: WP Symposium Pro Social Network plugin
Affected Version From: 15.12
Affected Version To: 15.12
Patch Exists: YES
Related CWE: Not assigned yet
CPE: a:wordpress:wp_symposium_pro_social_network_plugin
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016
WP Symposium Pro Social Network plugin
The 'wps_usermeta_shortcodes.php' file contains a parameter that is not sanitized, leading to persistent XSS. The edit profile page is vulnerable to CSRF, which allows for a password change and full account takeover.
Mitigation:
Update to version 16.1