vendor:
Quick Page/Post Redirect Plugin
by:
dxw
6,8
CVSS
MEDIUM
CSRF/XSS
352
CWE
Product Name: Quick Page/Post Redirect Plugin
Affected Version From: 5.0.3
Affected Version To: 5.0.5
Patch Exists: YES
Related CWE: CVE-2014-2598
CPE: 2.3:a:wordpress:quick_pagepost_redirect_plugin
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
CSRF and stored XSS in Quick Page/Post Redirect Plugin
This plugin is vulnerable to a combination CSRF/XSS attack meaning that if an admin user can be persuaded to visit a URL of the attacker’s choosing (via spear phishing for instance), the attacker can insert arbitrary JavaScript into an admin page. Once that occurs the admin’s browser can be made to do almost anything the admin user could typically do such as create/delete posts, create new admin users, or even exploit vulnerabilities in other plugins.
Mitigation:
Upgrade to version 5.0.5 or later.