Lucene search

K
wpexploitAsif Nawaz MinhasWPEX-ID:E934AF78-9DFD-4E14-853D-DC453DE6E365
HistoryAug 22, 2022 - 12:00 a.m.

WBW Currency Switcher for WooCommerce < 1.6.6 - Admin+ Stored XSS

2022-08-2200:00:00
Asif Nawaz Minhas
338
xss
stored
admin+
woocommerce
currency
switcher
frontend

EPSS

0.001

Percentile

24.8%

The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

In the plugin's settings (WooCommerce > Settings > Currency > Frontend Switcher), tick "Enable switcher" and put the following payload in the "Panel header text" settings: <img src onerror=alert(/XSS/)>

Save the settings. The XSS will be triggered when viewing the settings page again, as well as in any frontend page

EPSS

0.001

Percentile

24.8%

Related for WPEX-ID:E934AF78-9DFD-4E14-853D-DC453DE6E365