Title: WordPress 'Content Grabber' Plugin Version: 1.0 Author: Morten Nørtoft, Kenneth Jepsen & Mikkel Vej Date: 2015-06-14 Download: - https://wordpress.org/plugins/content-grabber/ - https://plugins.svn.wordpress.org/content-grabber/ Notified WordPress: 2015-06-21 ========================================================== ## Plugin description ========================================================== A plugin to help you grab content of any post type and display them as you want ## Vulnerabilities ========================================================== Two POST parameters (obj_field_name and obj_field_id) are printed unsanitized when the 'get_terms_taxonomies' action is executed. PoC: Log in as admin and submit the following request:





## Solution ========================================================== No fix available ========================================================== Vulnerabilities found using Eir; an early stage static vulnerability scanner for PHP applications.