Malware Devil

Tuesday, September 8, 2020

Reflected XSS in WordPress Plugin Admin Pages

Reflected XSS in WordPress Plugin Admin Pages

The administrative dashboard in WordPress is a pretty safe place: Only elevated users can access it. Exploiting a plugin’s admin panel would serve very little purpose here — an administrator already has the required permissions to do all of the actions a vulnerability could cause.

While this is usually true, there are a number of techniques bad actors are using to trick an administrator into performing actions they would not expect, such as Cross Site Request Forgery (CSRF) or Clickjacking attacks.

Continue reading Reflected XSS in WordPress Plugin Admin Pages at Sucuri Blog.

The post Reflected XSS in WordPress Plugin Admin Pages appeared first on Security Boulevard.

Read More

The post Reflected XSS in WordPress Plugin Admin Pages appeared first on Malware Devil.



https://malwaredevil.com/2020/09/08/reflected-xss-in-wordpress-plugin-admin-pages/?utm_source=rss&utm_medium=rss&utm_campaign=reflected-xss-in-wordpress-plugin-admin-pages

No comments:

Post a Comment

Barbary Pirates and Russian Cybercrime

In 1801, the United States had a small Navy. Thomas Jefferson deployed almost half that Navy—three frigates and a schooner—to the Barbary C...