vendor:
Duplicate-Post Plugin
by:
Unk9vvN
5.5
CVSS
MEDIUM
Persistent Cross-Site Scripting
79
CWE
Product Name: Duplicate-Post Plugin
Affected Version From: 3.2.2003
Affected Version To: 3.2.2003
Patch Exists: YES
Related CWE:
CPE: a:duplicate-post:plugin
Platforms Tested: Kali Linux
2019
Duplicate-Post 3.2.3 – Persistent Cross-Site Scripting
This vulnerability is in the validation mode and is located in the plugin management panel. The vulnerability allows an attacker to inject malicious script code in various fields, such as 'Title prefix', 'Title suffix', 'Increase menu order by', and 'Do not copy these fields'. By saving the changes, the payload will execute.
Mitigation:
Update to the latest version of the Duplicate-Post plugin to fix this vulnerability.