Lucene search

K
wpexploitWpvulndbWPEX-ID:287BDD2E-2B0A-4276-B44F-77DDA5F3E227
HistoryAug 29, 2022 - 12:00 a.m.

Visual Composer Website Builder < 45.0.1 - Authenticated Stored XSS via Title

2022-08-2900:00:00
wpvulndb
101
xss
authenticated
stored
title
plugin editor
post
payload
triggered
exploit

0.001 Low

EPSS

Percentile

19.4%

The plugin does not sanitise and escape post/page Title, which could allow users with access to the plugin’s editor to perform Cross-Site Scripting attacks

Create a post using the plugin editor and add the following payload in the Title: "><svg/onload=alert(/XSS/)>

The XSS will be triggered when editing the post again

0.001 Low

EPSS

Percentile

19.4%

Related for WPEX-ID:287BDD2E-2B0A-4276-B44F-77DDA5F3E227