Title: WordPress 'Google 'Plus one' Button by kms' Plugin Version: 1.5.0 Author: Morten Nørtoft, Kenneth Jepsen & Mikkel Vej Date: 2015-06-16 Download: - https://wordpress.org/plugins/google-plus-one-button-by-kms/ - https://plugins.svn.wordpress.org/google-plus-one-button-by-kms/ Notified WordPress: 2015-06-21 ========================================================== ## Plugin description ========================================================== WordPress bővítmény a Google +1 (plus one) gomb elhelyezésére. Megjeleníthető bejegyzés előtt, után, illetve az írások mellett bal oldalon ## CSRF/XSS vulnerabilities ========================================================== The _SERVER variable 'REQUEST_URI' is printed directly into the HTML on the admin page. The settings in the admin panel is vulnerable to stored XSS and the settings can be changed using an CSRF attack. PoC(s): Log in as admin and submit one of the following forms: XSS on admin pages:














XSS on pages displaying a Google Plus +1 button:










## Solution ========================================================== No fix available ========================================================== XSS vulnerabilities found using Eir; an early stage static vulnerability scanner for PHP applications.