26 Nov 2018

Vulnerability Details: Authenticated Persistent Cross-Site Scripting (XSS) in LoginPress

One of the changelog entries for version 1.1.14 of LoginPress is “Enhancement: Important Security update.” Looking at the changes made in the version we found that there were a number of security changes made. There may be something more serious that we didn’t notice, but what we noticed that seems of most concern is that previously the import functionality of the plugin was accessible to anyone logged in to WordPress and lacked protection against cross-site request forgery (CSRF). That could have been used to cause persistent cross-site scripting (XSS) by changing the plugin’s settings. A similar issue in a more popular plugin has recently drawn the interest of hackers.

...


This post provides insights on a vulnerability in the WordPress plugin LoginPress not discovered by us, where the discoverer hadn't provided the details needed for us to confirm the vulnerability while we were adding it to the data set for our service, so the rest of its contents are limited to subscribers of our service.

If you were using our service, you would have already been warned about this vulnerability if your website is vulnerable due to it. You can try out our service for free and then see the rest of the details of the vulnerability.

For existing customers, please log in to your account to view the rest of the contents of the post.

Leave a Reply

Your email address will not be published.