WordPress Cross-Site Scripting

Published on 26 Jun 2018
Vulnerability
XSS

Many servers use WordPress version 4.4-4.8.1, which is vulnerable to a Cross-Site Scripting (XSS) in oEmbed. An unauthenticated attacker can inject JavaScript code into WordPress comments. If these comments are improperly stored because of limitations on the MySQL TEXT data type. The script in the comment section will be triggered when the comment is viewed.

The oEmbed is an added extra hardening around allowed HTML for better security. The oEmbed is used for improved sandboxing.

Example

The following code will get executed under this vulnerability.

    <b onmouseover=alert('Wufff!')>click me!</b>

    

Impact and Fixes

Prathap
Written by
Co-founder, Director

Prathap has around 20 years of experience and has worked on various projects in leading companies like Hitachi, Toshiba, Schneider Electric, ABB, Panasonic, and MicroFuzzy. His expertise lies in architecting, designing, and developing secure projects covering various aspects of software development, processes, and methodology.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo