Authenticated Persistent Cross-Site Scripting (XSS) Vulnerability in WP GitHub Tools
Recently we were contacted by one of the users of our service, J.D. Grimes, who had found some possible vulnerabilities that involved shortcodes and a lack of escaping when passing data to the function wp_localize_script(). He was too busy to go further with them at the time and was wondering if we could take it from there in confirming them and getting in touch with the developers. One the impacted plugins was WP GitHub Tools.
The plugin registers the shortcode “chart” to call the function display_chart(): [Read more]