SmokeSignal <= 1.2.6 - Authenticated Stored XSS

Sign up to our free email alerts service for instant vulnerability notifications!

Description
Plugin description: "This plugin allows you to communicate with other registered users of you wordpress blog/website/portal easily inside admin interface."
Active installs (according to https://wordpress.org/plugins/smokesignal/): < 10

Messages aren't sanitized before they are displayed, so it's possible to inject <script> tags for example.

Low privileged accounts like subscribers can write message too.

Found by:

Paul Dannewitz

Other vulnerabilities I submitted to wpvulndb: https://wpvulndb.com/search?utf8=%E2%9C%93&text=Paul+Dannewitz

Affects Plugin

fixed in version 1.2.7

References

URL https://wordpress.org/plugins/smokesignal/

Classification

Type XSS
OWASP Top 10 A3: Cross-Site Scripting (XSS)
CWE CWE-79

Miscellaneous

Submitter Paul Dannewitz
Submitter Twitter padannewitz
Views 12
Verified No
WPVDB ID 8902

Timeline

Publicly Published 2017-09-02 (about 2 months ago)
Added 2017-09-19 (about 1 month ago)
Last Updated 2017-09-19 (about 1 month ago)

Copyright & License

Copyright All data and resources contained within this page and this web site is Copyright © The WPScan Team.
License Some of this data may be used for non-commercial purposes, however, any potential commercial usage of this data will require a license. If you would like to inquire about a commercial license please contact us.