CyberRota Analysis
AI-GeneratedThe Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping in the lpagery_add_filter_text_template_post() function, affecting versions up to 2.5.7. This flaw allows authenticated attackers with Contributor-level access or higher to inject malicious scripts into post titles, which can execute when higher-privileged users access specific admin pages. WordPress site administrators and developers using this plugin should prioritize patching this vulnerability to mitigate potential exploitation risks.
Original NVD Description
The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.5.7. This is due to insufficient input sanitization and output escaping in the lpagery_add_filter_text_template_post() function, which is hooked to admin_footer and echoes the raw post_title of the post referenced by the ?lpagery_template query parameter directly inside a JavaScript single-quoted string literal, without esc_js(), esc_html(), or any other encoding. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a higher-privileged user (such as an administrator) accesses an admin page with the ?lpagery_template=<post_id> parameter pointing at the attacker's post.