Lucene search

K
wpexploitFrancesco CarlucciWPEX-ID:A965AECA-D8F9-4070-AA0D-9C9B95493DDA
HistoryOct 26, 2021 - 12:00 a.m.

About Author Box < 1.0.2 - Contributor+ Stored Cross-Site Scripting

2021-10-2600:00:00
Francesco Carlucci
288
stored cross-site scripting
social profile fields
user interaction
low contributor role

EPSS

0.001

Percentile

24.8%

The plugin does not sanitise and escape the Social Profiles field values before outputting them in attributes, which could allow user with a role as low as contributor to perform Cross-Site Scripting attacks.

With a role as low as Contributor, put the following payloads in one of the Social Profile fields in your profile (/wp-admin/profile.php):
- javascript:alert(/XSS/)
- " style=animation-name:twentytwentyone-close-button-transition onanimationend=alert(/XSS/)//

The XSS will be triggered on posts published by the user and might require user interaction.

EPSS

0.001

Percentile

24.8%

Related for WPEX-ID:A965AECA-D8F9-4070-AA0D-9C9B95493DDA