Tarteaucitron WordPress Plugin Cross-Site Scripting Vulnerability via CSRF
Vulnerability
A stored cross-site scripting vulnerability has been identified in the Tarteaucitron WordPress plugin, affecting versions prior to 0.3.0. The issue arises from the plugin's lack of proper cross-site request forgery (CSRF) checks in certain areas, combined with inadequate data sanitization and escaping. This vulnerability could enable attackers to exploit logged-in administrators by injecting malicious scripts that are stored and executed later.
Impact
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.
Remediation
Users are advised to update the Tarteaucitron WordPress plugin to version 0.3.0 or later.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
