vendor:
WP Prayer
by:
Bastijn Ouwendijk
5.4
CVSS
MEDIUM
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: WP Prayer
Affected Version From: 1.6.1
Affected Version To: Earlier
Patch Exists: YES
Related CWE: CVE-2021-24313
CPE: 2.3:a:wordpress:wp_prayer
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2021
WordPress Plugin WP Prayer version 1.6.1 – ‘prayer_messages’ Stored Cross-Site Scripting (XSS) (Authenticated)
A stored cross-site scripting (XSS) vulnerability exists in WordPress Plugin WP Prayer version 1.6.1 and earlier. An authenticated user can inject malicious JavaScript code into the 'prayer_messages' field of the prayer request form. When the form is submitted, the malicious code is stored in the database and is executed when the page with the prayer requests is loaded. This can be used to steal user credentials or perform other malicious actions.
Mitigation:
Update to the latest version of the plugin.