Limited Black Friday Offer:
Security for everyone

WordPress Duplicate Page or Post < 1.5.1 - Stored XSS Vulnerability CVE-2021-25075 Scanner

Remote attacker can perform a stored cross site scripting attack (XSS) by injecting malicious payload.

SCAN NOW

Short Info


Level

Low

Type

Single Scan

Can be used by

Asset Owner

Estimated Time

10 sec

Scan only one

Domain, Ipv4

Parent Category

WordPress Duplicate Page or Post < 1.5.1 - Stored XSS Vulnerability CVE-2021-25075 Scanner Detail

The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings, or perform such attack via CSRF. Furthermore, due to the lack of escaping, this could lead to Stored Cross-Site Scripting issues