Lucene search

K
wpexploitWpvulndbWPEX-ID:65B9A54E-9BC7-4AA3-91A6-010F18896DBA
HistoryAug 31, 2020 - 12:00 a.m.

WP Floating Menu < 1.4.1 - Authenticated Reflected Cross-Site Scripting

2020-08-3100:00:00
wpvulndb
21

EPSS

0.001

Percentile

37.3%

The id GET parameter used by WP Floating menu does not correctly sanitise user input before reflecting the parameter back to the user, resulting in a reflected XSS vulnerability. Other sanitisation have been added to prevent other XSS issues as well as potential SQL injections.

/wp-admin/admin.php?page=wpfm-admin&action=wpfm-edit-menu&id=1"><script>alert(`XSS`)</script>

EPSS

0.001

Percentile

37.3%

Related for WPEX-ID:65B9A54E-9BC7-4AA3-91A6-010F18896DBA