Lucene search

K
wpexploitWpvulndbWPEX-ID:EA806115-14AB-4BC4-A272-2141CB14454A
HistoryApr 12, 2023 - 12:00 a.m.

ChatBot < 4.5.1 - Admin+ Stored XSS

2023-04-1200:00:00
wpvulndb
64
chatbot
admin+
stored xss
vulnerability
your company
website name
settings
exploit

0.001 Low

EPSS

Percentile

23.5%

The plugin does not sanitise and escape numerous of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Put the following payload in the Your Company or Website Name settings of the plugin and save: " style=animation-name:rotation onanimationstart=alert(/XSS/)//

All settings are affected

0.001 Low

EPSS

Percentile

23.5%

Related for WPEX-ID:EA806115-14AB-4BC4-A272-2141CB14454A