Lucene search

K
wpexploitDmitrii IgnatyevWPEX-ID:DA4D4D87-07B3-4F7D-BCBD-D29968A30B4F
HistoryMay 14, 2024 - 12:00 a.m.

Gutenberg Blocks by Kadence Blocks < 3.2.37 - Contributor+ Stored XSS

2024-05-1400:00:00
Dmitrii Ignatyev
38
gutenberg blocks
kadence blocks
stored xss
poc
may 28 2024
update

AI Score

5.9

Confidence

High

EPSS

0

Percentile

9.0%

Description The plugin does not validate and escape some of its block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Add a Lottie Animation block to a post and put the following payload in the "Lottie Animation URL" option of the block: https://lottie.host/9a802a6b-8684-423f-9eb3-c88be9caa335/QuOMXrIn7t.lottie" onmouseover=alert(/XSS/)//


The XSS will be triggered when any user will (pre)view the post and move the mouse over the generated image

AI Score

5.9

Confidence

High

EPSS

0

Percentile

9.0%

Related for WPEX-ID:DA4D4D87-07B3-4F7D-BCBD-D29968A30B4F