VDB-ID: 176
Title: Persistent XSS in wordpress plugin rockhoist-badges v1.2.2
Vulnerability Date: 2017-02-20
Download: https://wordpress.org/plugins/rockhoist-badges/
Vendor: https://profiles.wordpress.org/esserq/
Notified: 2017-02-20
Vendor Contact:
Description: A Stack Overflow inspired plugin for WordPress which allows users to acquire badges for contributing website content. Badges are created and managed through the WordPress Dashboard.
Vulnerability: There is a persistent cross site scripting vulnerability in the plugin Rockhoist Badges. A user with the
ability to edit_posts can inject malicious javascript. Into the badge description or title field.
Line 603 doesn't sanitize user input before sending it to the browser in file ./rockhoist-badges/rh-badges.php:
-> 603: Delete
CVEIDs: CVE-2017-6102
Exploit: "> in the title or description field will inject js.
URL: http://www.vapidlabs.com/advisory.php?v=176
Media: http://www.vapidlabs.com/m/badges.jpg
Credit: Larry W. Cashdollar, @_larry0