The Instant-Quote.co Quotation Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A Contributor-level user can trigger execution against higher-privileged users by embedding the malicious shortcode in a post submitted for review, causing the injected scripts to execute when an administrator previews or views the post.
The Instant-Quote.co Quotation Page WordPress plugin versions up to 1.3.4 contains a Stored Cross-Site Scripting vulnerability in shortcode attributes due to insufficient input sanitization. Authenticated contributors can inject malicious scripts that execute when administrators or other users access affected pages.
تحتوي إضافة Instant-Quote.co Quotation Page للووردبريس على ثغرة Stored XSS في سمات Shortcode بسبب عدم كفاية تنظيف المدخلات والتحقق من المخرجات. يمكن للمستخدمين المصرحين على مستوى المساهم حقن نصوص برمجية ضارة تُنفذ عند وصول المسؤولين أو المستخدمين الآخرين إلى الصفحات المتأثرة.
The Instant-Quote.co Quotation Page WordPress plugin versions up to 1.3.4 contains a Stored Cross-Site Scripting vulnerability in shortcode attributes due to insufficient input sanitization. Authenticated contributors can inject malicious scripts that execute when administrators or other users access affected pages.
Update the Instant-Quote.co Quotation Page plugin to version 1.3.5 or later immediately. Restrict contributor-level access to trusted users only. Implement Web Application Firewall rules to detect and block XSS payloads. Conduct security audit of all posts and pages created by contributors for malicious content.
قم بتحديث إضافة Instant-Quote.co Quotation Page إلى الإصدار 1.3.5 أو أحدث فوراً. قيد الوصول على مستوى المساهم للمستخدمين الموثوقين فقط. طبق قواعد جدار الحماية لتطبيقات الويب لكشف وحجب حمولات XSS. أجرِ تدقيق أمني لجميع المنشورات والصفحات التي أنشأها المساهمون بحثاً عن محتوى ضار.