vendor:
Easy Social Icons WordPress plugin
by:
Eric Flokstra - ITsec Security Services
5.5
CVSS
MEDIUM
XSS [CWE-79] and CSRF [CWE-352]
79, 352
CWE
Product Name: Easy Social Icons WordPress plugin
Affected Version From: 1.2.2002
Affected Version To: 1.2.2002
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2015
Easy Social Icons WordPress plugin
It is discovered that insufficient validation is performed on the 'image_file' parameter enabling arbitrary JavaScript to be injected. On top of that no random tokens are used to prevent CSRF attacks. By combining these vulnerabilities an attacker could for example trick an admin into setting a persistent XSS payload on the public WordPress page.
Mitigation:
Upgrade to version 1.2.3