S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 8, 2024

CVE-2023-0099 Scanner

CVE-2023-0099 scanner - Cross Site Scripting vulnerability in Simple URLs

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-0099
6.1
CVSS

The Simple URLs WordPress plugin before 115 does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Simple URLs
AFFECTED< 115SAFE ✓≥ 115
Updated Aug 22, 2026View on NVD →
Detail

Simple URLs is a WordPress plugin developed by GetLasso, designed to manage URL redirections and tracking for links within WordPress websites. It allows site administrators to create, manage, and track outbound links from their site, providing a cleaner way to manage affiliate links and other external links. The plugin is popular among WordPress users for its simplicity and effectiveness in organizing links and monitoring click-through rates. It is particularly useful for marketers, bloggers, and website owners looking to optimize their external link management. However, like any software, it is subject to potential security vulnerabilities that need to be addressed to prevent exploitation.

The Cross Site Scripting (XSS) vulnerability in the Simple URLs plugin before version 115 arises from the lack of proper sanitization and escaping of some parameters before they are outputted back in certain pages. This oversight allows attackers to inject malicious scripts into web pages viewed by other users. Reflected XSS attacks are particularly dangerous as they can be used to execute scripts in the context of a high-privilege user's session, potentially leading to unauthorized actions such as session hijacking and sensitive data theft.

Specifically, the vulnerability is present in the admin assets of the Simple URLs plugin, where the 'search' parameter is not properly sanitized in the import-js.php file. An attacker can craft a malicious URL containing a script tag or other JavaScript code snippet. When this URL is visited by a user with sufficient privileges, such as an administrator, the malicious code is executed in their browser. This can lead to various security breaches, including the stealing of session cookies, personal data, or even manipulation of website content.

If exploited, the XSS vulnerability in Simple URLs can have severe consequences, including session hijacking, where an attacker takes control of a user's session to gain unauthorized access to the WordPress dashboard. It can also lead to the defacement of websites, where attackers alter the appearance or content of the site without permission. Additionally, sensitive information belonging to the website or its users could be stolen and used for malicious purposes, and in some cases, it may enable attackers to perform remote code execution on the affected site.

By leveraging the security scanning services offered by S4E, users can identify vulnerabilities such as the XSS issue in the Simple URLs plugin before they are exploited. Our platform provides detailed vulnerability assessments, including identification, impact analysis, and remediation recommendations. By becoming a member, you'll gain access to continuous monitoring and expert guidance, helping to protect your website against current and emerging threats. Joining S4E ensures that your website remains secure, maintaining the trust of your users and safeguarding your online presence.

 

References

Solution Advice
  1. Immediately update the Simple URLs plugin to version 115 or later, which contains the necessary fixes for this XSS vulnerability.
  2. Regularly update all WordPress plugins and themes to their latest versions to mitigate potential security vulnerabilities.
  3. Implement a web application firewall (WAF) to detect and block XSS and other types of attacks.
  4. Conduct periodic security reviews and scans of your WordPress site to identify and address vulnerabilities.
  5. Educate users with administrative access about the risks of XSS and other types of web security threats to promote vigilant and safe web practices.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.