WordPress Blubrry PowerPress 6.0 Cross Site Scripting
WordPress Blubrry PowerPress 6.0 Cross Site Scripting
WordPress Blubrry PowerPress 6.0 Cross Site Scripting

Blubrry PowerPress 6.0 (WP WordPress Blubrry PowerPress 6.0 Cross Site Scripting

Blubrry PowerPress 6.0 (WP Plugin) - XSS
Advisory ID: RO-15-001
CVE ID: CVE-2015-1385
Severity: Medium
Vendor: Blubrry
Product: PowerPress WordPress Plugin
Version: 6.0


Overview #

A Cross-site Scripting (XSS) vulnerability exists in Blubrry PowerPress WordPress Plugin version 6.0. The vulnerability allows remote attackers to inject arbitrary web script or HTML.


Vulnerability Details #

Affected Versions: 6.0 and earlier

Root Cause: Insufficient input validation and output encoding allows attackers to inject malicious scripts.


Exploitation Requirements #

No authentication required
Victim must visit a crafted URL or page

Impact #

Remote attackers can exploit this vulnerability to:

Steal WordPress admin session cookies
Perform actions on behalf of admin users
Compromise the WordPress installation

Proof of Concept #

Details available upon request.


Solution #

Upgrade to a patched version of PowerPress that includes proper input sanitization and output encoding.


References #

CVE-2015-1385

Timeline:

[2015-01-01] - Discovered

Credits: Omar Kurt
Social Media Share
About Contact Terms of Use Privacy Policy
© Khalil Shreateh — Cybersecurity Researcher & White-Hat Hacker — Palestine 🇵🇸
All content is for educational purposes only. Unauthorized use of any information on this site is strictly prohibited.