Lucene search

K
wpexploitShivam RaiWPEX-ID:ECDDB611-DE75-41D5-A470-8FC2CF0780A4
HistoryOct 11, 2021 - 12:00 a.m.

Qwizcards < 3.62 - Admin+ Stored Cross Site Scripting

2021-10-1100:00:00
Shivam Rai
271

0.001 Low

EPSS

Percentile

24.8%

The plugin does not properly sanitize and escape some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Within Settings > Qwizcards > Qwizcardsa Option, put the following payload in the Qwizcards-content HTML field
v < 3.61 - "><script>alert(/XSS/)</script>
v < 3.62 - " autofocus onfocus=alert(/XSS/)//

0.001 Low

EPSS

Percentile

24.8%

Related for WPEX-ID:ECDDB611-DE75-41D5-A470-8FC2CF0780A4