An advisory was issued for the Ocean Additional WordPress plugin that’s vulnerable to saved cross-site scripting, which allows attackers to add malicious scripts that execute on the location when a person visits the affected web site.
Ocean Additional WordPress Plugin
The vulnerability impacts solely the Ocean Additional plugin by oceanwp, a plugin that extends the favored OceanWP WordPress theme. The plugin provides additional options to the OceanWP theme, comparable to the power to simply host fonts regionally, further widgets, and expanded navigation menu choices.
In response to the Wordfence advisory, the vulnerability is because of inadequate enter sanitization and output escaping.
Enter Sanitization
Enter sanitization is the time period used to explain the method of filtering what’s enter into WordPress, like in a type or any subject the place a person can enter one thing. The objective is to filter out surprising sorts of enter, like malicious scripts**,** for instance. That is one thing that the plugin is claimed to be lacking (inadequate).
Output Escaping
Output escaping is sort of like enter sanitization however within the different path, a safety course of that makes certain that no matter is being output from WordPress is secure. It checks that the output doesn’t have characters that may be interpreted by a browser as code and subsequently executed, comparable to what’s present in a saved cross-site scripting (XSS) exploit. That is the opposite factor that the Ocean Additional plugin was lacking.
Collectively, the inadequate enter sanitization and inadequate output escaping allow attackers to add a malicious script and have it output on the WordPress web site.
Customers Urged To Replace Plugin
The vulnerability solely impacts authenticated customers with contributor-level privileges or larger, to a sure extent mitigating the menace degree of this particular exploit. This vulnerability impacts variations as much as and together with model 2.4.9. Customers are suggested to replace their plugin to the newest model, at present 2.5.0.
Featured Picture by Shutterstock/Nithid