PT-2019-7781 · WordPress · Leenkme Plugin
Shravan Kumar
·
Publicado
2019-09-17
·
Atualizado
2019-09-17
·
CVE-2016-10988
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
leenkme plugin versions prior to 2.6.0
Description
The issue concerns stored XSS in the leenkme plugin for WordPress. It can be exploited via variables such as
facebook message, facebook linkname, facebook caption, facebook description, default image, or wp http referer.Recommendations
For versions prior to 2.6.0, update to version 2.6.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the variables
facebook message, facebook linkname, facebook caption, facebook description, default image, and wp http referer until the update is applied.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Leenkme Plugin