# Exploit Title: Wordpress ALO EasyMail Newsletter CSRF/XSS # Exploit Author: Ashiyane Digital Security Team # Vendor Homepage: https://wordpress.org/plugins/alo-easymail/ # Software Link: https://downloads.wordpress.org/plugin/alo-easymail.2.6.00.zip # Version: 2.6 # Date: 2015-09-15 # Tested on: windows 7 /FireFox #################################################### #Exploit :
#################################################################### # Vulnerable File : /wp-content/plugins/alo-easymail/pages/alo-easymail-admin-options.php # Vulnerable codes: Line 484 : ================================= For Patch XSS : Replace Line 484 With: ########################################################## discovered by : Amir.ght(Goldhack)