Executive brief
The ZhinaTwitterWidget is a WordPress plugin that integrates Twitter content into websites. An unauthenticated attacker can inject malicious JavaScript into the page through reflected cross-site scripting (XSS), allowing them to steal visitor session cookies, deface website content, or redirect users to phishing sites without requiring any special access.
Technical details
This is a reflected cross-site scripting (XSS) vulnerability in the ZhinaTwitterWidget WordPress plugin version 1.0 and earlier. The plugin fails to properly sanitize or validate user input when generating web pages, allowing an attacker to inject arbitrary JavaScript code. The vulnerability requires user interaction (clicking a malicious link or visiting a crafted page), but no authentication is needed. An unauthenticated attacker can exploit this to steal session tokens, perform actions on behalf of logged-in users, or compromise the integrity of the web page. No official patch is currently available; mitigation rules have been issued by Patchstack.
Affected products
- zckevin ZhinaTwitterWidget through 1.0
Timeline
- 2025-03-20: disclosed
- other: Reported to Patchstack on 2024-10-30