Executive brief
The eShop plugin for WordPress, which provides shopping cart functionality, contains a security flaw that allows attackers to run malicious scripts in a user's browser. By tricking a user into clicking a specially crafted link, an attacker could potentially steal login sessions or perform actions on behalf of the user. This affects the order management component of the plugin.
Technical details
Multiple reflected cross-site scripting (XSS) vulnerabilities exist in eshop-orders.php within the eShop plugin version 6.3.14 for WordPress. The vulnerability is caused by a failure to sanitize the 'page' and 'action' GET parameters before echoing them back into the HTML response, specifically within administrative links and hidden input fields. A remote attacker can exploit this by crafting a malicious URL and tricking a victim (typically an administrator) into visiting it. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized administrative actions.
Affected products
- Richard Pedley eShop plugin 6.3.14
Timeline
- 2016-01-27: disclosed: Vulnerability discovered by Larry W. Cashdollar
- 2016-01-29: other: Vendor notified
- 2017-01-23: advisory: NVD advisory published