Web / CMS

Cross-Site Scripting (XSS)

Stagtools < 2.3.7 - Contributor+ Stored XSS

Stagtools < 2.3.7 – Contributor+ Stored XSS The plugin does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which

5.4
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS71
PUBLISHED
2023-06-19
CVE IDs
CVE-2023-0891
VENDORS
Codestag
PUBLIC EXPLOIT
PoC public
CWE
CWE-79
PRODUCT
Stagtools (WordPress plugin)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Stagtools < 2.3.7 – Contributor+ Stored XSS

The plugin does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Vulnerability details

Vulnerability details

CVE-2023-0891
CWE-79
Medium | 5.4

Stagtools < 2.3.7 – Contributor+ Stored XSS The plugin does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to

Auth:
Any authenticated user (remote, user interaction required)
Impact:
Limited data disclosure, limited data tampering; impact extends beyond the vulnerable component
DISCLOSURE

Disclosure timeline

2023-02-11 Reported On

2023-04-05 Made Public On

2023-03-23 Fixed On

Credits

Manash Saikia