Need a Wordpress developer who has experience in OWASP / Pentest / VAPT

Job ID: 32105325

Budget: $30 – $250 SGD

We have an urgent task now for a VAPT (Pentest) fixes > Grey box testing.
We need to fix the following issue (Stored Cross-Site Scripting) on a customised Wordpress plugin in which admin can enter course details and will be displayed on the frontend.

Stored Cross-Site Scripting

Description:
It was observed that the affected parameter/s were vulnerable to Cross-Site
Scripting (XSS). The payloads were stored in the database and inserted into the
web pages without proper encoding.

Note: This finding is systemic to the application. The list above is not exhaustive, and any new pages created would also be vulnerable to cross-site scripting. The requests and responses below show the evidence for the first affected URL. The steps to replicate for the other URLs remain largely the same and have been omitted for brevity.

Solution:
To block all js scripts and html tags, and whitelist only a certain (common) html tags (e.g. <p>, <b>, <u>, etc.)

****** Please only respond if you have successful experience with this ******

Thank you.
Related categories: PHP JavaScript Web Security WordPress MySQL