Lucene search

K
wpexploitBob MatyasWPEX-ID:715DED45-04EE-40C1-8ACB-BD40D0FE30EC
HistoryJan 23, 2024 - 12:00 a.m.

Better Follow Button for Jetpack <= 8.0 - Admin+ Stored XSS

2024-01-2300:00:00
Bob Matyas
24
jetpack
stored xss
admin+ module
vulnerability
exploit
cross-site scripting
website security

7.9 High

AI Score

Confidence

High

0 Low

EPSS

Percentile

0.0%

Description The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

1. Navigate to: https://example.com/wp-admin/admin.php?page=better-follow-button-for-jetpack%2Fsettings.php
2. Add the payload to the "Main Button" field (other fields are likely vulnerable as well): "><script>alert(1)</script>
3. Click "Save Changes" and see the XSS.

7.9 High

AI Score

Confidence

High

0 Low

EPSS

Percentile

0.0%

Related for WPEX-ID:715DED45-04EE-40C1-8ACB-BD40D0FE30EC