[FD] Google Analytics by Yoast stored XSS #2

2015-04-21 Thread Jouko Pynnonen
*Overview* Google Analytics by Yoast is one of the most popular WordPress plug-ins with over 7 million downloads and "1+ million" active installs. Last month Yoast patched a stored XSS we reported in the plug-in. Shortly after this we identified another bug of a similar severity. The second stored

[FD] Google Analytics by Yoast stored XSS

2015-03-19 Thread Jouko Pynnonen
*Overview* Google Analytics by Yoast is a WordPress plug-in for monitoring website traffic. With approximately seven million downloads it’s one of the most popular WordPress plug-ins. A security vulnerability in the plug-in allows an unauthenticated attacker to store arbitrary HTML, including Jav