Lucene search

K
wpexploitZhangyunpeiWPEX-ID:96818024-57AB-419D-BD46-7D2DA98269E6
HistoryNov 30, 2022 - 12:00 a.m.

Sliderby10Web < 1.2.53 - Admin+ Stored XSS

2022-11-3000:00:00
zhangyunpei
107
sliderby10web
admin
stored xss
sliders
edit
slide options
save
xss popup
exploit

EPSS

0.001

Percentile

25.3%

The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

1. Go to "Slider ยป Sliders" and edit one of the Sliders or add a new one. 

2. Click the "Slide options" and enter: 1" onmouseenter="alert(/XSS/)" ", in the input box named "Link the slide to". 

3. Click Save ยป refresh the page, and hover the mouse over the input box under 'Slide options' to check the XSS popup.

EPSS

0.001

Percentile

25.3%

Related for WPEX-ID:96818024-57AB-419D-BD46-7D2DA98269E6