CVE-2020-37225

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary JavaScript by exploiting unsanitized input fields in plugin settings. Attackers can submit malicious payloads through textarea and input elements in the pwhois_settings.php configuration page to execute JavaScript in the admin context and escalate privileges.

<p>Checks Domain WHOIS Lookup for availability. Simple insert the [pwhois] shortcode on a page or post.<br /> To select the default TLD use the default attribute: [pwhois default=com] &#8211; sets .com as default in the TLD dropdown.<br /> TLD List is limited because of the knowledge of the required whois servers. If you wish to have support for a special TLD please contact me and I will implement it asap.<br /> We cannot guarantee that every domain lookup works perfect, in case that whois servers and how to talk to them can change time by time.<br /> However if you inform us about changes and we can get it to work, we give you a free version of the Pro version of this plugin!</p> <h4>Demos</h4> <p><a href="https://powie.de/wordpress/whois/" rel="nofollow ugc">Demo 1</a> &#8211; at our own page.</p> <p><a href="https://be-webspace.de/domaincheck/" rel="nofollow ugc">Demo 2</a> &#8211; live version at a hosting providers webpage.</p> <h4>Requires</h4> <ul> <li>php7</li> </ul> <h4>Including:</h4> <ul> <li>Shortcode [pwhois]</li> </ul> <h4>Support</h4> <p>Support Forum @ <a href="https://forum.powie.de/forum/87-powies-whois/" rel="nofollow ugc">forum.powie.de</a><br /> You get faster feedback if you post in our forum, rather than on wordpress.org!</p> <h3>Remove plugin</h3> <ol> <li>Deactivate plugin through the &#8216;Plugins&#8217; menu in WordPress</li> <li>Delete plugin through the &#8216;Plugins&#8217; menu in WordPress</li> </ol>
WordPress Plugin DirectoryWordPress Plugin Directory
31K