PT-2021-8385 · WordPress · Clickbank Affiliate Ads

Ethicalhack3R

+1

·

Published

2021-12-02

·

Updated

2021-12-04

·

CVE-2015-20105

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ClickBank Affiliate Ads WordPress plugin versions 1.20 and earlier
Description The issue arises from the lack of a CSRF check when saving settings, allowing an attacker to manipulate a logged-in admin into changing them via a CSRF attack. Additionally, the lack of escaping when outputting settings can lead to Stored Cross-Site Scripting issues.
Recommendations For ClickBank Affiliate Ads WordPress plugin versions 1.20 and earlier, update to a version that includes a CSRF check and proper escaping of output settings to prevent these issues. As a temporary workaround, consider restricting access to the settings page to minimize the risk of exploitation.

Exploit

Fix

XSS

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-20105

Affected Products

Clickbank Affiliate Ads