XSS Vulnerability reported on TagDiv sites and themes by Openbugbounty.org

Posted in: Newspaper
Post count: 436

Hi, Today morning, I received an email from openbugbounty.org claiming a security vulnerability on my website. On further checking, I discovered that this issue was reported by user called “npuser500′ here is the link to the user, https://www.openbugbounty.org/researchers/npuser500/

On further research, I noticed that this user has also reported the same error on Tagdiv.com and demo.tagdiv.com sites as well.

The security reports can be read here : https://www.openbugbounty.org/reports/279730/
https://www.openbugbounty.org/reports/279729/

The reported security issue is called “XSS vulnerability” which can be used for ”
Cross Site Scripting”. It appears that this can be related to WordPress and hance affecting to all WordPress based site. Is this a real security concern? What should I do or what are you planning to do?

The reporter’s email ID is “sirujam@vivaldi.net” should we contacted him for resolution or we can resolve this issue by ourselves.

Kindly help me with this.

Thank you.

Post count: 22421

Hello,

We have looked into this but it is a very “marginal” security risk happening in extremely specific cases and is very hard to exploit. In our initial tests we have not been able to replicate what the article mentions but we will investigate further as we take security very seriously. For the moment there is no immediate threat that can affect users. It is a very minor risk if any at all. We will however release a new update in the near future and we have added this on our priority list for the next update. We will most likely implement a fix for it even though it is not a big security risk but it’s best to be on the safe side.

For the moment it is not a concern for the general public.

Thank you!

Post count: 436

Thank you so much, Bogdan, for looking into it.

Post count: 24

Hi,

Even I received a similar email from openbugbounty.org. Here are the contents of the email:

—————————–
Dear IT Security Team,

This is a notification email about a security vulnerability on your website – completewellbeing.com
A security researcher has reported it via coordinated disclosure Open Bug Bounty program: https://www.openbugbounty.org/reports/279741/

We verified and confirmed that the vulnerability exists and is exploitable. To keep your website safe and prevent exploitation of the vulnerability while it’s unpatched, technical details are not publicly visible during at least 30 days, and 90 days if the vulnerability is unpatched. Please contact the security researcher directly for further details and assistance: https://www.openbugbounty.org/researchers/npuser500/

You can also customize your vulnerability notification alerts to send them directly to right people in your organization: https://www.openbugbounty.org/email-alerts/

If you received this notification by error, please accept our apologizes and forward it to your IT security team, or a person in charge of your website security.
Have a nice day and stay secure,

OpenBugBounty Team
Making Web Safer

DISCLAIMER: The Open Bug Bounty project (www.openbugbounty.org) has no direct or indirect relations with security researchers. Our sole mission is to verify submissions and notify website owners as soon as possible in order to keep their websites safe.
———————————–

As per Bogdan’s response, the vulnerability will be patched in the next upgrade. So as I understand, we stay put and take no action right now. Is that correct?

Post count: 20685

Hi,

Yes that is correct. The subject will be analyzed by our developer team and we will take the appropriate measures in this regard.

Thanks

Viewing 5 posts - 1 through 5 (of 5 total)
You must be logged in to reply to this topic.