Lucene search

K
wpexploitAsif Nawaz MinhasWPEX-ID:11C89925-4FE9-45F7-9020-55FE7BBAE3DB
HistorySep 20, 2022 - 12:00 a.m.

We’re Open! < 1.42 - Admin+ Stored Cross-Site Scripting

2022-09-2000:00:00
Asif Nawaz Minhas
207
vulnerability
cross-site scripting
admin access

EPSS

0.001

Percentile

24.8%

The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Put the following payload in the Settings > We're Open > Separators & Text > Closed Text: "><svg/onload=alert(/XSSTEST/)>

Save the settings, the XSS will be triggered on pages/posts where the Closed Text is displayed, for example when [open] is embed is there is at least one closed day

EPSS

0.001

Percentile

24.8%

Related for WPEX-ID:11C89925-4FE9-45F7-9020-55FE7BBAE3DB