• Vulnerability: XSS
  • Affected Software: NextScripts: Social Networks Auto-Poster (100,000+ active installations)
  • Affected Version: 4.2.7
  • Patched Version: 4.2.8
  • Risk: Medium
  • Vendor Contacted: 10/25/2018
  • Vendor Fix: 11/02/2018
  • Public Disclosure: 02/05/2019
CVSS

6.1 Medium CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

The Social Networks Auto-Poster WordPress plugin is vulnerable to reflected XSS as it echoes the item parameter without proper encoding.

Successful exploitation allows an attacker to execute JavaScript in the context of the application in the name of an attacked user. This in turn enables an attacker to bypass CSRF protection and thus perform any actions the legitimate user can perform, as well as read data which the user can access.

Proof of Concept
http://192.168.0.103/wordpress/wp-admin/admin.php?page=nxssnap-reposter&action=edit&item=24'"><img+src%3Dx+onerror%3Dalert(1)>
Code
social-networks-auto-poster-facebook-twitter-g/inc/nxs_class_mgmt.php
<form method="post" id="nxs_form_rep"> <input name="pid" value="<?php echo $_GET['item']; ?>" type="hidden" />
Timeline
  • 10/25/2018 Requested email address via contact form
  • 10/29/2018 Vendor supplies email address
  • 10/31/2018 Advisory sent
  • 11/02/2018 Vendor releases fix
  • 02/05/2019 Confirmed fix & Disclosure