vendor:
Tagregator
by:
ManhNho
4.8
CVSS
MEDIUM
Stored XSS
79
CWE
Product Name: Tagregator
Affected Version From: 0.6
Affected Version To: 0.7.1
Patch Exists: YES
Related CWE: CVE-2018-10752
CPE: 2.3:a:wordpress:tagregator
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: CentOS 6.5
2018
WordPress Plugin Tagregator 0.6 – Cross-Site Scripting
WordPress Plugin Tagregator 0.6 is vulnerable to a stored cross-site scripting vulnerability. An attacker can inject malicious JavaScript code into the title field of the plugin's settings page, which is then stored in the database. When another administrator visits the page, the malicious code is executed.
Mitigation:
To mitigate this vulnerability, users should update to the latest version of the plugin, which is version 0.7.1.