SmokeSignal <= 1.2.6 - Authenticated Stored XSS



Description
Plugin description: "This plugin allows you to communicate with other registered users of you wordpress blog/website/portal easily inside admin interface."
Active installs (according to https://wordpress.org/plugins/smokesignal/): < 10

Messages aren't sanitized before they are displayed, so it's possible to inject <script> tags for example.

Low privileged accounts like subscribers can write message too.

Found by:

Paul Dannewitz

Other vulnerabilities I submitted to wpvulndb: https://wpvulndb.com/search?utf8=%E2%9C%93&text=Paul+Dannewitz

Affects Plugin

fixed in version 1.2.7

References

URL https://wordpress.org/plugins/smokesignal/

Classification

Type XSS
OWASP Top 10 A3: Cross-Site Scripting (XSS)
CWE CWE-79

Miscellaneous

Submitter Paul Dannewitz
Submitter Twitter padannewitz
Views 3755
Verified No
WPVDB ID 8902

Timeline

Publicly Published 2017-09-02 (almost 2 years ago)
Added 2017-09-19 (almost 2 years ago)
Last Updated 2017-09-19 (almost 2 years ago)