Lucene search

K
wpexploitJrXnmWPEX-ID:B960CB36-62DE-4B9F-A35D-144A34A4C63D
HistoryNov 15, 2021 - 12:00 a.m.

Pixel Cat Lite < 2.6.3 - Admin+ Stored Cross-Site Scripting

2021-11-1500:00:00
JrXnm
97
pixel cat lite
cross-site scripting
plugin vulnerability
google product category
e-commerce
woocommerce

EPSS

0.001

Percentile

24.8%

The plugin does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

Put the following payload in the Google Product Category setting of the plugin (at wp-admin/admin.php?page=fca_pc_settings_page in the E-Commerce > Advanced Feed Settings, needs WooCommerce activated): ' style=animation-name:rotation onanimationstart=alert(/XSS/)//

The XSS will be trigged when showing the setting again

EPSS

0.001

Percentile

24.8%

Related for WPEX-ID:B960CB36-62DE-4B9F-A35D-144A34A4C63D