Can Anyone Fix the Security Issue?
-
This is a valuable plugin and I suspect that it is used by many others and not just me. For my uses it provides critical functionality. There is an open security issue. I have not looked into the code yet but was hoping maybe the original developer would do that.
The Exifography plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only impacts multi-site installations and installations where unfiltered_html has been disabled.
The topic ‘Can Anyone Fix the Security Issue?’ is closed to new replies.