Lucene search

K
wpexploitDmitrii IgnatyevWPEX-ID:EA2A8420-4B0E-4EFB-A0C6-CEEA996DAE5A
HistoryMar 25, 2024 - 12:00 a.m.

Responsive Tabs < 4.0.7 - Contributor+ Stored XSS

2024-03-2500:00:00
Dmitrii Ignatyev
28
wordpress
tab sets
stored xss
security exploit
request interception

5.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Description The plugin does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

1. Go to "Tab Sets > Add New" in WP Admin
2. Add a new tab and fill out values.
3. Intercept the request and for the `tabs_color` parameter, add the payload `"+onmouseover='alert(1)'"`
4. Send the request and then preview the tab group to see the XSS

5.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Related for WPEX-ID:EA2A8420-4B0E-4EFB-A0C6-CEEA996DAE5A