*XSS and Uncontrolled redirect Vulns in Encrypted Blog Plugin for Wordpress* # Date: 28 August 2013 # Author: k3170makan # Vendor or Software Link: http://wordpress.org/plugins/encrypted-blog/ # Version: 0.0.6.2 # Category: webapps # Tested on: N/A The Encrypted Blog Plug-in for Wordpress suffers from multiple vulnerabilities exposing authenticated wordpress users to Cross Site Scripting attacks and Uncontrolled redirects and via a combination of these vulnerabilities a leakage of the Encryption key set by the wordpress user. *Cross Site Scripting:* The contents of the redirect_to field in the encrypt_blog_form.php, which is supplied via GET method is not sanitized and allows attackers to submit malicious HTML/JavaScript and other client side browser scripting content. Here's the code: from https://github.com/marcusds/EncryptedBlog/blob/master/encrypted_blog_form.php 13