vendor:
Relevanssi
by:
Saif El-Sherei
7.5
CVSS
HIGH
Stored XSS
79
CWE
Product Name: Relevanssi
Affected Version From: Relevanssi 2.7.2
Affected Version To: Relevanssi 2.7.2
Patch Exists: YES
Related CWE: N/A
CPE: 2.7.2/wordpress/3.0.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: FireFox 3.6.13, IE 8
2011
Relevanssi User Searches WordPress plugin Stored XSS
A stored XSS vulnerability exists due to 'search Query' variable is displayed & logged unsanitized in the 'User Searches' section in the admin Dashboard, allowing an attacker to inject malicious HTML code.
Mitigation:
Update to latest plugin version.