vendor:
WP24 Domain Check
by:
Mehmet Kelepçe / Gais Cyber Security
7.5
CVSS
HIGH
Stored Cross Site Scripting
79
CWE
Product Name: WP24 Domain Check
Affected Version From: 1.6.2002
Affected Version To: 1.6.2002
Patch Exists: YES
Related CWE:
CPE: a:wordpress:wp24_domain_check:1.6.2
Platforms Tested: Apache2 - Windows 10
2021
WordPress Plugin WP24 Domain Check 1.6.2 – ‘fieldnameDomain’ Stored Cross Site Scripting
The 'fieldnameDomain' parameter in the WP24 Domain Check plugin for WordPress version 1.6.2 is vulnerable to stored cross-site scripting (XSS) attacks. An attacker can inject malicious JavaScript code into the 'fieldnameDomain' field, which will be executed when the field is focused. This can lead to session hijacking, cookie theft, and other malicious activities.
Mitigation:
Update to the latest version of the WP24 Domain Check plugin (1.6.3 or later) which contains a patch for this vulnerability. Additionally, it is recommended to sanitize and validate user input before displaying it on the website to prevent XSS attacks.