Description
WordPress Plugin uCan Post is prone to multiple HTML injection vulnerabilities because it fails to properly sanitize user-supplied input. Attacker supplied HTML and script code could be executed in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks may also be possible. WordPress Plugin uCan Post version 1.0.09 is vulnerable; other versions may also be affected.
Remediation
Edit the source code to ensure that input is properly sanitised or disable the plugin until a fix is available
References
Related Vulnerabilities
Oracle Database Server Resource Management Errors Vulnerability (CVE-2007-5506)
WordPress Plugin WP Social Bookmarking Light Cross-Site Scripting (1.7.9)
WordPress Plugin ZoomSounds-WordPress Wave Audio Player with Playlist Arbitrary File Upload (2.0)
WordPress Plugin PowerPress Podcasting by Blubrry Cross-Site Scripting (10.0.1)