Title: WordPress 'Advertisement Management' Plugin Version: 1.0 Author: Morten Nørtoft, Kenneth Jepsen & Mikkel Vej Date: 2015-06-16 Download: - https://wordpress.org/plugins/advertisement-management/ - https://plugins.svn.wordpress.org/advertisement-management/ Notified WordPress: 2015-06-21 ========================================================== ## Plugin description ========================================================== Advertisement Management lets you administrate all the blog advertisements diretctly from the blog backend. ## XSS/CSRF vulnerabilities ========================================================== The settings on the admin page is vulnerable to XSS. PoC: Log in as admin and submit the this form








After having done this, some of the injected scripts will be executed when loading the front page of the site. ## Solution ========================================================== No fix available ========================================================== XSS vulnerabilities found using Eir; an early stage static vulnerability scanner for PHP applications.