###################### # Exploit Title : Wordpress Monetize Plug-in XSS/CSRF # Exploit Author : Ashiyane Digital Security Team # Vendor Homepage : https://wordpress.org/plugins/monetize/ # Date: 2015-08-07 # Tested On : Kali Linux - FireFox # Software Link : https://downloads.wordpress.org/plugin/monetize.zip # Version : 1.03 ###################### # Vulnerable Code: File: class-monetize-zones-list-table.php - Line 45 $zone_name_link = ''.$item['zone_name'].''; ###################### # Exploit:
# Explain: Use this exploit to add a "zone" which has malicious code and then if admin goes to page "View All Zones" (URL: /wp-admin/admin.php?page=monetize-zones) your code will execute. ###################### # Patch: File: class-monetize-zones-list-table.php - Line 45 $zone_name_link = ''.htmlspecialchars($item['zone_name']).''; ###################### # Discovered By : Mahdi.Hidden ######################