Lucene search

K
wpexploitLana CodesWPEX-ID:4869FDC7-4FC7-4917-BC00-B6CED9CCC871
HistoryFeb 16, 2023 - 12:00 a.m.

Campaign URL Builder < 1.8.2 - Contributor+ Stored XSS

2023-02-1600:00:00
Lana Codes
132
campaign url builder
stored xss
shortcode settings
bitly api key
plugin vulnerability
exploit
attribute vulnerabilities
advanced settings

0.001 Low

EPSS

Percentile

23.3%

The plugin does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

The shortcode need to be active (can be done via the Shortcode tab settings of the plugin), and a bitly API key set (can be a dummy one such as 'aaa') via the Advanced settings of the plugin

[Campaign-URL-Builder wrapper='" onmouseover="alert(/XSS/)"']

Other attributes were also affected (such as wrapper-inline-style, form-inline-style, input-class, form and custom_parameters)

0.001 Low

EPSS

Percentile

23.3%

Related for WPEX-ID:4869FDC7-4FC7-4917-BC00-B6CED9CCC871