PT-2026-73087 · WordPress · Platnosci Online Blue Media
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Platnosci Online Blue Media (Autopay) plugin for WordPress versions prior to 5.0.1
Description
Stored Cross-Site Scripting occurs via the
bm woocommerce css editor content POST parameter. The Css Editor::handle save() function is linked to the WordPress init hook by Settings Manager::init once() without capability checks, nonce verification, or input sanitization. This allows unauthenticated attackers to write raw data to the woocommerce bluemedia settings option using update option(). The content is subsequently rendered without output escaping within a style block on the WooCommerce checkout page by Css Frontend::print to wp head(), enabling the execution of arbitrary web scripts when a user visits the affected page.Recommendations
Update the Platnosci Online Blue Media (Autopay) plugin for WordPress to version 5.0.1 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Platnosci Online Blue Media