Lucene search

K
wpexploitShweta MahajanWPEX-ID:9C315404-B66A-448C-A3B7-367A37B53435
HistoryNov 15, 2021 - 12:00 a.m.

Security Audit <= 1.0.0 - Admin+ Stored Cross Site Scripting

2021-11-1500:00:00
Shweta Mahajan
35
security audit
admin
stored cross site scripting
vulnerability
exploit

EPSS

0.001

Percentile

38.3%

The plugin does not sanitise and escape the Data Id setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Put the following payload in the Data ID setting of the plugin (/wp-admin/edit.php?post_type=tlsa_audit&page=tlsa_settings) and save them: "><img src=x onerror=confirm(/XSS/)>

EPSS

0.001

Percentile

38.3%

Related for WPEX-ID:9C315404-B66A-448C-A3B7-367A37B53435