vendor:
Soliloquy Lite
by:
Unk9vvN
5.5
CVSS
MEDIUM
Persistent Cross-Site Scripting
79
CWE
Product Name: Soliloquy Lite
Affected Version From: 2.5.2006
Affected Version To: 2.5.2006
Patch Exists: YES
Related CWE:
CPE: a:wordpress:soliloquy_lite:2.5.6
Platforms Tested: Kali Linux
2019
WordPress Soliloquy Lite 2.5.6 – Persistent Cross-Site Scripting
This vulnerability is in the validation mode and is located in the Preview of new post inside soliloquy. The vulnerability occurs when a user inserts a script tag in the title input and saves the post. The vulnerability is triggered when the target clicks on the preview of the post.
Mitigation:
Update to the latest version of Soliloquy Lite