12 Nov 2018

Vulnerability Details: Reflected XSS Vulnerability in PeepSo

The quality of reports on vulnerabilities in WordPress plugins are not always great and a report of a reflected cross-site scripting (XSS) vulnerability in the plugin PeepSo released today is a perfect example of that. The report claims that there is a vulnerability in version 1.11.2 of the plugin and doesn’t indicate whether it was fixed. That version hasn’t been the latest version of the plugin for over a month, so did that mean that it was fixed or did the discloser not bother checking if more recent version were impacted? Making that more difficult to decipher the discloser provided no details beyond a proof of concept.

...


This post provides insights on a vulnerability in the WordPress plugin PeepSo not discovered by us, where the discoverer hadn't provided the details needed for us to confirm the vulnerability while we were adding it to the data set for our service, so the rest of its contents are limited to subscribers of our service.

If you were using our service, you would have already been warned about this vulnerability if your website is vulnerable due to it. You can try out our service for free and then see the rest of the details of the vulnerability.

For existing customers, please log in to your account to view the rest of the contents of the post.

Leave a Reply

Your email address will not be published.