vendor:
Postie
by:
V1n1v131r4
5.4
CVSS
MEDIUM
Persistent Cross-Site Scripting
79
CWE
Product Name: Postie
Affected Version From: 1.9.40
Affected Version To: 1.9.40
Patch Exists: YES
Related CWE: CVE-2019-20203, CVE-2019-20204
CPE: 2.3:a:wordpress:postie:1.9.40
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2020
WordPress Plugin Postie 1.9.40 – Persistent Cross-Site Scripting
Postie is a WordPress plugin that allows users to post to their blog via email. Postie versions 1.9.40 and below are vulnerable to persistent cross-site scripting (XSS) due to improper input validation. An attacker can craft a malicious email with a polyglot JavaScript syntax and a crafted SVG to perform a persistent XSS attack. This can allow an attacker to execute arbitrary JavaScript code in the context of the vulnerable website.
Mitigation:
Users should upgrade to Postie version 1.9.41 or later to mitigate this vulnerability.