Lucene search

K
wpexploitSwapnil bodekarWPEX-ID:DC2CE546-9DA1-442C-8EE2-CD660634501F
HistoryAug 02, 2021 - 12:00 a.m.

SMS Alert Order Notifications – WooCommerce < 3.4.7 Authenticated Cross Site Scripting

2021-08-0200:00:00
swapnil bodekar
315

0.001 Low

EPSS

Percentile

37.5%

The plugin is affected by a cross site scripting (XSS) vulnerability in the plugin’s setting page.

Enter the payload below for the "SMS Alert Username" in the plugin's settings.

"+onfocus="alert(1)"+autofocus="

You will observe that the  JavaScript payload successfully got reflected is and we are getting a pop-up.

0.001 Low

EPSS

Percentile

37.5%

Related for WPEX-ID:DC2CE546-9DA1-442C-8EE2-CD660634501F