PT-2019-7380 · WordPress · Olevmedia Shortcodes

Published

2019-09-26

·

Updated

2019-09-26

·

CVE-2015-9421

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions olevmedia-shortcodes plugin versions prior to 1.1.9
Description The issue concerns a CSRF with resultant XSS in the olevmedia-shortcodes plugin for WordPress. This occurs via the "wp-admin/admin-ajax.php?action=omsc popup" API endpoint, specifically through the id parameter.
Recommendations For versions prior to 1.1.9, update to version 1.1.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the "wp-admin/admin-ajax.php?action=omsc popup" API endpoint to minimize the risk of exploitation. Avoid using the id parameter in this endpoint until the issue is resolved.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-9421

Affected Products

Olevmedia Shortcodes