A vulnerability was discovered on WordPress plugin ZOHO CRM Lead Magnet 1.6.9.1. An input variable vulnerable to XSS are ‘Module,’ ‘EditShortcode,’ and ‘LayoutName’ in the Zoho CRM form creation page. A vulnerability allows an attacker to inject malicious code into the WordPress plugin ZOHO CRM Lead magnet by providing XSS payload as a value for vulnerable variables.
Figure 01: Zoho CRM Lead Magnet.
Figure 02: Client key and secret id are filled in Authenticating Zoho CRM Plugin..png)
.png)
Figure 06: The JavaScript is successfully executed in the victim browser context.
Figure 07: The WordPress application runs on version 5.2.3.
Figure 08: The WordPress Zoho CRM Lead Magnet Plugin Version: 1.6.9.1.
Figure 09: The default cross-site scripting mitigation setting in wp.config file to prevent Cross-Site Scripting attacks.