Lucene search

K
wpexploitShivam RaiWPEX-ID:300BA418-63ED-4C03-9031-263742ED522E
HistorySep 06, 2021 - 12:00 a.m.

Modern Events Calendar Lite < 5.22.2 - Admin+ Stored Cross-Site Scripting

2021-09-0600:00:00
Shivam Rai
301

0.001 Low

EPSS

Percentile

24.8%

The plugin does not escape some of its settings before outputting them in attributes, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Go to the plugin Settings > Messages > Taxonomies (/wp-admin/admin.php?page=MEC-settings&tab=MEC-messages)

Put the following payload in the Category Plural Label, Category Plural Label or Label Plural Label fields: "><script>alert(/XSS/)</script>

The XSS will be triggered in any backend pages

0.001 Low

EPSS

Percentile

24.8%

Related for WPEX-ID:300BA418-63ED-4C03-9031-263742ED522E