Authenticated Stored Cross-Site Scripting (XSS) vulnerability in WordPress Absolutely Glamorous Custom Admin plugin (versions <= 6.8). Stored XSS possible via unsanitized input fields of the plugin settings, some of the payloads could make the frontend and the backend inaccessible.
References
| Link | Resource |
|---|---|
| https://www.youtube.com/watch?v=tnyIIWntOww | Exploit Third Party Advisory |
| https://plugins.svn.wordpress.org/ag-custom-admin/trunk/changelog.txt | Release Notes Third Party Advisory |
| https://patchstack.com/database/vulnerability/ag-custom-admin/wordpress-absolutely-glamorous-custom-admin-plugin-6-8-authenticated-stored-cross-site-scripting-xss-vulnerability | Third Party Advisory |
Configurations
Information
Published : 2021-09-23 17:15
Updated : 2021-09-29 20:01
NVD link : CVE-2021-36823
Mitre link : CVE-2021-36823
JSON object : View
Products Affected
cusmin
- absolutely_glamorous_custom_admin
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
