Stored XSS in WordPress Employee Directory Plugin via 'emd_mb_meta' Shortcode
The Employee Directory – Staff Listing & Team Directory Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'emd_mb_meta' shortcode in all versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
emarket-design employee directory – staff listing & team directory plugin for wordpress |