Beta

Report

Organization chart <= 1.5.0 is vulnerable to Authenticated (Subscriber+) Stored Cross-Site Scripting via title_input and node_description Parameters vulnerability

Subscriber
Published
2024-08-06

The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_input’ and 'node_description' parameter in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, this can only be exploited by administrators, but the ability to use and configure charts can be extended to subscribers.

CVSS

Score:6.5

Severity:Medium

Version: 1.5.0

There is a patch available in v1.5.1 and we strongly recommend you update to this version as soon as possible.