vendor:
Better WP Security Plugin
by:
Richard Warren
7,5
CVSS
HIGH
Unauthenticated Stored XSS to RCE
79
CWE
Product Name: Better WP Security Plugin
Affected Version From: 3.4.8
Affected Version To: 3.5.3
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WordPress
2013
Bit51 Better WP Security Plugin – Unauthenticated Stored XSS to RCE
The Better Security Wordpress Plugin logs all 404 errors within the 'logs' tab. By purposefully requesting a non-existent page containing an XSS payload a 404 error will be generated. When the admin clicks on the logs lab, the XSS payload will be triggered and cookies can be stolen, or some onsite request forgery can be carried out to gain admin access.
Mitigation:
Ensure that all users are running the latest version of the Better WP Security Plugin.