Lucene search

K
wpexploitFrancesco CarlucciWPEX-ID:28007C80-DC14-4987-A52C-F2A05CFE5905
HistoryNov 09, 2021 - 12:00 a.m.

Get Custom Field Values < 4.0.1 - Contributor+ Stored Cross-Site Scripting

2021-11-0900:00:00
Francesco Carlucci
82

0.001 Low

EPSS

Percentile

25.0%

The plugin does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

As a contributor, create a custom field in a post, with the following payload: <script>alert(1)</script>

Then add the following shortcode to the post: [custom_field field="<custom_field_name>"]

0.001 Low

EPSS

Percentile

25.0%

Related for WPEX-ID:28007C80-DC14-4987-A52C-F2A05CFE5905