vendor:
iLive - Intelligent WordPress Live Chat Support Plugin
by:
m0ze
7.5
CVSS
HIGH
Stored XSS Injection
79
CWE
Product Name: iLive - Intelligent WordPress Live Chat Support Plugin
Affected Version From: 1.0.4
Affected Version To: 1.0.4
Patch Exists: NO
Related CWE: N/A
CPE: a:wpapplab:ilive_-_intelligent_wordpress_live_chat_support_plugin
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 / Parrot OS
2019
iLive – Intelligent WordPress Live Chat Support Plugin v1.0.4 Stored XSS Injection
Weak security measures like bad textarea data filtering has been discovered in the «iLive - Intelligent WordPress Live Chat Support Plugin». Current version of this premium WordPress plugin is 1.0.4. An attacker can use their payload inside an input field and press [Enter] to exploit the vulnerability. This can be used to steal admin cookies or force a redirect to any other website.
Mitigation:
Developers should ensure that all user input is properly sanitized and validated before being used in the application.