Vigil@nce - WordPress Recommend to a friend: Cross Site Scripting

This bulletin was written by Vigil@nce : http://vigilance.fr/offer

SYNTHESIS OF THE VULNERABILITY

An attacker can trigger a Cross Site Scripting of WordPress
Recommend to a friend, in order to execute JavaScript code in the
context of the web site.

Impacted products: WordPress Plugins

Severity: 2/4

Creation date: 30/12/2013

DESCRIPTION OF THE VULNERABILITY

The Recommend to a friend plugin can be installed on WordPress.

However, it does not filter received data before inserting them in
generated HTML documents.

An attacker can therefore trigger a Cross Site Scripting of
WordPress Recommend to a friend, in order to execute JavaScript
code in the context of the web site.

ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN

http://vigilance.fr/vulnerability/WordPress-Recommend-to-a-friend-Cross-Site-Scripting-14002

Articles similaires

Security Vulnerability

7 October 2026

Vigilance.fr - Adminer: multiple vulnerabilities dated 07/08/2026

An attacker can use several vulnerabilities of Adminer, dated 07/08/2026.

Security Vulnerability

7 October 2026

Vigilance.fr - Progress Telerik UI for AJAX: multiple vulnerabilities dated 07/08/2026

An attacker can use several vulnerabilities of Progress Telerik UI for AJAX, dated 07/08/2026.

Security Vulnerability

7 October 2026

Vigilance.fr - TeamPass: two vulnerabilities dated 07/08/2026

An attacker can use several vulnerabilities of TeamPass, dated 07/08/2026.