Mihdan: No External Links <= 4.7.4 - Cross-Site Scripting

2022-05-27 00:00
Vaibhav Nitin Gaikwad

Strategic Overview

Status
Patched in 4.8.0
Affected PluginNo External Links
Affected Version<= 4.7.4
CVSS5.5Medium
CVECVE-2022-1095
View all No External Links vulnerabilities

Vulnerability Overview

The Mihdan: No External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including 4.7.4. This makes it possible for admin level attackers to inject arbitrary web scripts on web pages that execute whenever another administrator accesses the page. This can be exploited on multi-site installations and installations where unfiltered_html is disabled.

Technical Analysis

REMEDIATION: Update to version 4.8.0, or a newer patched version --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C