Lucene search

K
wpexploitYuyudhnWPEX-ID:90EBAEDC-89DF-413F-B22E-753D4DD5E1C3
HistorySep 05, 2022 - 12:00 a.m.

Slider Hero < 8.4.4 - Admin+ Stored Cross-Site Scripting

2022-09-0500:00:00
yuyudhn
211
slider hero
cross-site scripting
stored xss
admin+

0.001 Low

EPSS

Percentile

24.8%

The plugin does not escape the slider Name, which could allow high-privileged users to perform Cross-Site Scripting attacks.

Create or edit a Slide and put the following payload in the Name field: " onfocus=alert(/XSS/) autofocus="

The XSS will be triggered when editing the slide again

0.001 Low

EPSS

Percentile

24.8%

Related for WPEX-ID:90EBAEDC-89DF-413F-B22E-753D4DD5E1C3