Lucene search

K
wpexploitShivam RaiWPEX-ID:0A46AE96-41E5-4B52-91C3-409F7387AECC
HistorySep 28, 2021 - 12:00 a.m.

WP Reactions Lite < 1.3.6 - Authenticated Stored Cross Site Scripting

2021-09-2800:00:00
Shivam Rai
255

0.001 Low

EPSS

Percentile

24.8%

The plugin does not properly sanitize inputs within wp-admin pages, allowing users with sufficient access to inject XSS payloads within /wp-admin/ pages.

* Open  Global Activation and Click on Customize Now
* On Step3 (StylingTab) >> Enter the XSS payload into "Whats your reaction" field
Payload Used : "><script>alert(document.location)</script>
* Click On Save and Exit Button and Alert will popup every time a Global Activation step is loaded.

0.001 Low

EPSS

Percentile

24.8%

Related for WPEX-ID:0A46AE96-41E5-4B52-91C3-409F7387AECC