PT-2021-8385 · WordPress · Clickbank Affiliate Ads
Ethicalhack3R
+1
·
Published
2021-12-02
·
Updated
2021-12-04
·
CVE-2015-20105
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ClickBank Affiliate Ads WordPress plugin versions 1.20 and earlier
Description
The issue arises from the lack of a CSRF check when saving settings, allowing an attacker to manipulate a logged-in admin into changing them via a CSRF attack. Additionally, the lack of escaping when outputting settings can lead to Stored Cross-Site Scripting issues.
Recommendations
For ClickBank Affiliate Ads WordPress plugin versions 1.20 and earlier, update to a version that includes a CSRF check and proper escaping of output settings to prevent these issues. As a temporary workaround, consider restricting access to the settings page to minimize the risk of exploitation.
Exploit
Fix
XSS
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Clickbank Affiliate Ads