WordPress Plugin Post Snippets Contains CSRF/Cross-Site Scripting (XSS) Vulnerability
A week ago, one of the moderators of the WordPress support forum deleted a topic titled “[Post Snippets] v3.1.3 – Stored Cross-Site Scripting (XSS) vulnerability“. The moderator’s message in deleting that said “Please report vulnerabilities responsibly.” If there was a really a vulnerability being reported, the moderator didn’t make sure it was addressed, as the plugin hasn’t been updated in the past week.
After we got alerted about the deletion message, we looked at the plugin and found that it does at least contain a cross-site scripting (XSS) vulnerability that can be exploited through cross-site request forgery (CSRF). [Read more]