Lucene search

K
wpexploitFayçal CHENAWPEX-ID:39E127F1-C36E-4699-892F-3755EE17BAB6
HistoryMay 18, 2022 - 12:00 a.m.

Carousel CK <= 1.1.0 - Admin+ Stored Cross-Site Scripting

2022-05-1800:00:00
Fayçal CHENA
66
carousel ck stored cross-site scripting page/post_embed exploit

EPSS

0.001

Percentile

24.8%

The plugin does not sanitize and escape Slide’s descriptions, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed

Create/edit a Carousel, add a Slide and put the following payload in the Description <img src onerror=alert(/XSS/)>

The XSS will be triggered in page/post where the Carousel is embed

EPSS

0.001

Percentile

24.8%

Related for WPEX-ID:39E127F1-C36E-4699-892F-3755EE17BAB6