Yoast Duplicate Post
cpe:2.3:a:duplicate_post_project:duplicate_post:*:*:*:*:wordpress:*:*
- <= 3.2.3
A persistent cross-site scripting vulnerability has been identified in the Yoast Duplicate Post WordPress plugin, specifically in version 3.2.3. This vulnerability allows attackers to inject malicious scripts into various plugin settings fields, including the title prefix, title suffix, menu order, and blacklist. The injected scripts are then executed as arbitrary JavaScript in the admin interfaces.
Exploitation of this vulnerability allows for persistent cross-site scripting, where injected scripts are executed in the context of the user interface.
To reproduce this vulnerability, navigate to the 'Settings' section of the Yoast Duplicate Post plugin. Enter a script payload into the 'Title prefix', 'Title suffix', 'Increase menu order by', and 'Do not copy these fields' sections. After saving the changes, the injected script will execute, demonstrating the cross-site scripting vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.