WP Prayer <= 1.6.1 - Authenticated Stored Cross-Site Scripting

2021-05-17 00:00
Bastijn Ouwendijk

Strategic Overview

Status
Patched in 1.6.2
Affected PluginWP Prayer
Affected Version< 1.6.2
CVSS6.4Medium
CVECVE-2021-24313
View all WP Prayer vulnerabilities

Vulnerability Overview

The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them on a WordPress website. These stored prayer/praise requests can be listed by using the WP Prayer engine. An authenticated WordPress user with any role can fill in the form to request a prayer. The form to request prayers or praises have several fields. The 'prayer request' and 'praise request' fields do not use proper input validation and can be used to store XSS payloads.

Technical Analysis

REMEDIATION: Update to version 1.6.2, or a newer patched version --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C