Lucene search

K
wpexploitAsif Nawaz MinhasWPEX-ID:9579FF13-9597-4A77-8CB9-997E35265D22
HistoryAug 02, 2021 - 12:00 a.m.

Sitewide Notice WP < 2.3 - Authenticated Stored XSS

2021-08-0200:00:00
Asif Nawaz Minhas
321
wordpress
stored xss
message setting
frontend pages
exploit

EPSS

0.001

Percentile

24.8%

The plugin does not sanitise some of its settings before outputting them in frontend pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Put the following payload in the Message setting of the plugin: <script>alert(/XSS/)</script>

The XSS will be triggered in all frontend pages

EPSS

0.001

Percentile

24.8%

Related for WPEX-ID:9579FF13-9597-4A77-8CB9-997E35265D22