vendor:
Powie's WHOIS Domain Check
by:
mqt
7.5
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: Powie's WHOIS Domain Check
Affected Version From: <0.9.31
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: a:powie:powie's_whois_domain_check:0.9.31
Platforms Tested: Wordpress
2020
WordPress Plugin Powie’s WHOIS Domain Check 0.9.31 – Persistent Cross-Site Scripting
Powie's WHOIS Wordpress plugin was found to be vulnerable to Stored XSS as multiple fields in the plugin's setup settings fail to properly sanitize user input. The risk here is mitigated due to the fact that active exploitation would require authentication. However a lower privileged Wordpress user would be able to take advantage of the fact that the arbitrary Javascript executes on the same origin and therefore by using a specially crafted payload, an attacker would be able to elevate their privileges or take any of the same actions an admin would be able to. All Wordpress websites using Powie's WHOIS version < 0.9.31 are vulnerable.
Mitigation:
Upgrade to version 0.9.31 or later.