Advertisement






WordPress Facebook Like Button 2.32 Cross Site Scripting

CVE Category Price Severity
CVE-2015-9251 CWE-79 $500 High
Author Risk Exploitation Type Date
Unknown High Remote 2015-12-17
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2015120188

Below is a copy:

WordPress Facebook Like Button 2.32 Cross Site ScriptingPlugin Name : Facebook Like Button
 
Effected Version : 2.32 (and most probably lower version's if any)
 
Vulnerability : A3-Cross-Site Scripting (XSS)
 
Identified by : Madhu Akula
 

 
Technical Details
 
Minimum Level of Access Required : Administrator
 
PoC - (Proof of Concept) :
 
The following field put the payload as below
 
 
http://localhost/wp-admin/admin.php?page=facebook-button-plugin.php
 
 
fcbkbttn_link = ><script>alert(1)</script>
 
 
Vulnerable Parameter : fcbkbttn_link
 
 
Type of XSS : Reflected
 
Fixed in : 2.33
 
http://wordpress.org/plugins/facebook-button-plugin/changelog/
 
Disclosure Timeline
 
Vendor Contacted : 2014-08-04
 
Plugin Status : Updated on 2014-08-07
 
Public Disclosure : October 3, 2015
 
CVE Number : Not assigned yet
 
Plugin Description :
 
Facebook Like Button Plugin allows you to add a Follow button the easiest way. If your life is tightly connected with your Facebook account, our plugin is the best solution for you. It contains minimum settings. Just a few clicks and voila - the Facebook button is on your site.


Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.