TelSender
- <= 1.14.14
A DOM-based cross-site scripting vulnerability has been identified in the TelSender plugin for WordPress, affecting all versions through 1.14.14. The issue arises from inadequate input sanitization when handling responses from the Telegram API that include chat titles controlled by attackers. This vulnerability allows unauthenticated attackers to inject malicious scripts via Telegram chat titles. These scripts are executed when an administrator accesses the TelSender settings page and clicks the 'Tested' button.
Exploitation of this vulnerability allows for unauthenticated stored cross-site scripting, where injected scripts are executed in the context of the user viewing the affected page.
To reproduce this vulnerability, an attacker can send a message to a Telegram chat that includes a script payload in the chat title. Once the message is received, an administrator can open the TelSender settings page in WordPress, where the injected script will execute upon clicking the 'Tested' button.
Users are advised to update the TelSender WordPress plugin to version 1.14.15 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.