MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance Plugin <= 3.1.2 - Stored Cross-Site Scripting
78Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 7.2epss 1.3%
from disclosure to weapon435 days
Published on NVDOct 16
1st PoC+435d
VulnCheckOct 15
exploitation probability
1.3%top 33% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
The MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mwp_setup_purchase_username’ parameter in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
public PoCs found — 2
vulncheckvulncheck.com/xdb/798cdd55d50funverifiedvulncheckvulncheck.com/xdb/4a63e86e53c2unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://klikki.fi/adv/mainwp.htmlhttps://web.archive.org/web/20191101060009/https%3A//klikki.fi/adv/mainwp.htmlhttps://www.acunetix.com/vulnerabilities/web/wordpress-plugin-mainwp-dashboard-cross-site-scripting-3-1-2/https://www.wordfence.com/threat-intel/vulnerabilities/id/a9b1445f-3b6b-40fa-9a12-f55d63668dda?source=cve