The quotes-collection plugin before 2.0.6 for WordPress has XSS via the wp-admin/admin.php?page=quotes-collection page parameter.
References
Link | Resource |
---|---|
https://sumofpwn.nl/advisory/2016/cross_site_scripting_vulnerability_in_quotes_collection_wordpress_plugin.html | Exploit Patch Third Party Advisory |
https://wordpress.org/plugins/quotes-collection/#developers | Third Party Advisory |
https://wpvulndb.com/vulnerabilities/8649 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2019-09-13 13:15
Updated : 2024-02-28 17:08
NVD link : CVE-2016-10952
Mitre link : CVE-2016-10952
CVE.ORG link : CVE-2016-10952
JSON object : View
Products Affected
quotes_collection_project
- quotes_collection
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')