Lucene search

K
wpexploitBob MatyasWPEX-ID:F0DE62E3-5E85-43F3-8E3E-E816DAFB1406
HistoryJun 05, 2024 - 12:00 a.m.

Video Widget <= 1.2.3 - Admin+ Stored XSS via Widget

2024-06-0500:00:00
Bob Matyas
9
vulnerability
update reminder
poc date
security

5.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

Description The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

1. Add a "Video Widget" to a widget area
2. Add the payload `"><script>alert(2222)</script>` for the "width" value
3. Save and see the XSS

Note: other fields are likely vulnerable

5.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

Related for WPEX-ID:F0DE62E3-5E85-43F3-8E3E-E816DAFB1406