
XSS in WordPress
Vulnerability: Cross-site scripting in WordPress Video Lead Form
Danger: Low
Patch: Yes
Number of vulnerabilities: 1
Vector of operation: Remote
Impact: Cross Site Scripting
Affected products: WordPress Video Lead Form Plugin 0.x
Affected versions: WordPress Video Lead Form 0.5, maybe earlier.
Description:
The vulnerability allows malicious people to conduct XSS attacks.
The vulnerability is caused due to insufficient input validation in the parameter ‘errMsg’ in script wp-admin/admin.php (when the parameter ‘page’ is ‘video-lead-form’). This can be exploited to execute arbitrary HTML and script code in a user’s browser session in context of an affected site.
Manufacturer URL: http://wordpress.org/extend/plugins/video-lead-form/
Solution: Install the latest version 0.6 from the manufacturer.
links:
http://packetstormsecurity.org/files/118466/WordPress-Video-Lead-Form-0.5-Cross-Site-Scripting.html