Lucene search

K
wpexploitShreya PohekarWPEX-ID:2B59F640-5568-42BB-87B7-36EB448DB5BE
HistoryJun 19, 2023 - 12:00 a.m.

Image Protector <= 1.1 - Admin+ Stored Cross-Site Scripting

2023-06-1900:00:00
Shreya Pohekar
48
image protector
admin+
stored xss
cross-site scripting
exploit

0.001 Low

EPSS

Percentile

19.5%

The plugin does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

1. Go to http://example.com/wp-admin/admin.php?page=image-protector%2Fimage-protector.php.

2. Paste the payload in the user agent check input field: </textarea><script>alert(1008)</script>

3. Save changes, and XSS will be triggered.

0.001 Low

EPSS

Percentile

19.5%

Related for WPEX-ID:2B59F640-5568-42BB-87B7-36EB448DB5BE