Description

WordPress Plugin uCan Post is prone to multiple HTML injection vulnerabilities because it fails to properly sanitize user-supplied input. Attacker supplied HTML and script code could be executed in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks may also be possible. WordPress Plugin uCan Post version 1.0.09 is vulnerable; other versions may also be affected.

Remediation

Edit the source code to ensure that input is properly sanitised or disable the plugin until a fix is available

References

Related Vulnerabilities