PT-2026-98383 · WordPress · Ssl Zen
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SSL Zen plugin for WordPress versions prior to 4.7.43
Description
Reflected Cross-Site Scripting occurs when unauthenticated attackers trick users into clicking specially crafted links to inject arbitrary web scripts. The issue exists because the
ssl zen messages::getMessages() function constructs the 'token missmatch' message by decoding the uri and host parameters using base64 decode(). Since sanitize text field() cannot detect malicious scripts hidden within base64-encoded data, the decoded raw HTML is subsequently echoed unescaped by the showMessage() function.Recommendations
Update the plugin to a version newer than 4.7.42.
As a temporary mitigation, restrict or avoid the use of the
uri and host parameters until the update is applied.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ssl Zen