WordPress Application Passwords Plugin Reflected Cross-Site Scripting Vulnerability
Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Application Passwords plugin for WordPress, affecting all versions through 0.1.3. The issue arises from inadequate input sanitization and output escaping of user-supplied URLs, allowing the injection of javascript: URI schemes into the reject_url parameter. This vulnerability enables unauthenticated attackers to inject arbitrary web scripts that execute when a user clicks the 'No, I do not approve of this connection' button, provided the attacker can successfully deceive the victim into clicking a link.
Impact
Exploitation of this vulnerability allows for reflected cross-site scripting, where injected scripts are executed in the context of the user's browser.
Remediation
No known patch is available. It is recommended to review the vulnerability details and consider uninstalling the affected plugin.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
