PT-2026-63576 · WordPress · Post Status Notifier Lite
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Post Status Notifier Lite versions prior to 1.13.0
Description
Insufficient escaping of the
mod URL parameter in the admin settings page endpoint 'admin.php?page=post-status-notifier-lite' allows for Reflected Cross-Site Scripting. This occurs when an administrator is tricked into following a specially crafted URL, causing the script to execute within their session.Recommendations
Update Post Status Notifier Lite to version 1.13.0 or later.
Avoid using the
mod parameter in the 'admin.php?page=post-status-notifier-lite' endpoint until the update is applied.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Post Status Notifier Lite