#28610 closed defect (bug) (invalid)
Persistent XSS and CSRF on wordpress 3.9.1
| Reported by: | avinash_thapa | Owned by: | nacin |
|---|---|---|---|
| Priority: | normal | Milestone: | |
| Component: | General | Version: | 3.9.1 |
| Severity: | normal | Keywords: | |
| Cc: | Focuses: |
Description
As you release the new version of wordpress 3.9.1.
It consists of multiple vulnerabilities i.e Persistent XSS and CSRF.
This is present in the comment box.
An attaker can easily put the simple xss vector and able to create the XSS there.
It is a critical Vulenrability as it is stored.
Attachments (1)
Change History (5)
#1
@
12 years ago
- Milestone Awaiting Review
- Resolution → invalid
- Status new → closed
When creating this ticket, was "Do not report potential security vulnerabilities here. See the Security FAQ and contact security@…." not noticeable? Honest question. If you have JavaScript enabled, you additionally would have needed to click a checkbox affirming "I am not reporting a security issue — report security issues to security@…".
Your report is invalid. Please read https://codex.wordpress.org/Roles_and_Capabilities#unfiltered_html
![(please configure the [header_logo] section in trac.ini)](/chrome/site/your_project_logo.png)
PoC of the vulnerability