RSS   Vulnerabilities for 'Shiny buttons'   RSS

2021-12-13
 
CVE-2021-24792

CWE-79
 

 
The Shiny Buttons WordPress plugin through 1.1.0 does not have any authorisation and CSRF in place when saving a template (wpbtn_save_template function hooked to the init action), nor sanitise and escape them before outputting them in the admin dashboard, which allow unauthenticated users to add a malicious template and lead to Stored Cross-Site Scripting issues.

 


Copyright 2024, cxsecurity.com

 

Back to Top