Progressive License <= 1.1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting

2022-07-07 00:00
Daniel Ruf

Strategic Overview

Status
Unpatched
Affected PluginProgressive License
Affected Version<= 1.1.0
CVSS6.1Medium
CVECVE-2022-2171
View all Progressive License vulnerabilities

Vulnerability Overview

The Progressive License WordPress plugin through 1.1.0 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the settings, this could lead to Stored XSS issue which will be triggered in the frontend as well.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C