PT-2026-63592 · WordPress · Lpagery
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Lpagery versions prior to 2.5.8
Description
Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping in the
lpagery add filter text template post() function. The function is hooked to admin footer and echoes the raw post title of a post referenced by the lpagery template query parameter directly inside a JavaScript single-quoted string literal without proper encoding. Authenticated attackers with Contributor-level access or higher can inject arbitrary web scripts that execute when a higher-privileged user, such as an administrator, accesses an admin page using the lpagery template parameter pointing to the attacker's post.Recommendations
Update to a version newer than 2.5.7.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lpagery