Executive brief
En Masse is a WordPress plugin for bulk editing and content management. A reflected cross-site scripting (XSS) vulnerability allows attackers to inject malicious scripts that execute in visitors' browsers when they click a crafted link, potentially stealing session data, credentials, or hijacking user accounts.
Technical details
The vulnerability is an improper neutralization of user input during web page generation, classified as reflected XSS. It affects En Masse plugin version 1.0 and earlier. The vulnerability requires user interaction (victim must click a malicious link), but does not require authentication to exploit. An attacker can craft a malicious URL containing JavaScript payload that executes in the context of the victim's browser session, allowing theft of cookies, session tokens, or account hijacking. No official patch is currently available according to Patchstack.
Affected products
- Matamko En Masse <= 1.0
Timeline
- 2025-03-19: disclosed: Published by Patchstack
- 2024-10-30: other: Reported by João Pedro S Alcântara (Kinorth)