Executive brief
ZD Scribd iPaper is a WordPress plugin that embeds Scribd documents on web pages. The plugin fails to properly filter user input, allowing attackers to inject malicious JavaScript code. An attacker can craft a malicious link and trick site visitors into clicking it, enabling them to steal login credentials, session tokens, or customer data from the affected site.
Technical details
The vulnerability is a reflected cross-site scripting (XSS) flaw in the ZD Scribd iPaper WordPress plugin (versions through 1.0) caused by improper neutralization of user-controlled input during web page generation. The attack is network-accessible and requires no authentication, but successful exploitation requires user interaction (clicking a malicious link). An unauthenticated attacker can inject arbitrary JavaScript into the page, which executes in the context of the victim's browser. No official patch has been released as of the disclosure date (31 October 2024), though Patchstack provides a mitigation rule to block exploitation attempts.
Affected products
- Proloy Chakroborty ZD Scribd iPaper <= 1.0
Timeline
- 2025-12-31: disclosed
- 2025-03-20: advisory