Stored XSS Vulnerability in Campus Directory WordPress Plugin via Shortcode Attributes
The Campus Directory plugin for WordPress contains a Stored Cross-Site Scripting vulnerability through its 'emd_mb_meta' shortcode in versions up to 1.9.0. The vulnerability stems from inadequate input sanitization and output escaping of user-supplied attributes. Authenticated attackers with contributor-level or higher permissions can inject malicious web scripts that will execute when other users access the compromised pages.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
emarket-design campus directory – faculty, staff & student directory plugin for wordpress |