Lucene search

K
wpvulndbBob MatyasWPVDB-ID:02CA09F8-4080-4969-992D-0E6AFB29BC62
HistoryMay 24, 2024 - 12:00 a.m.

Social Pixel <= 2.1 - Admin+ Stored XSS

2024-05-2400:00:00
Bob Matyas
wpscan.com
3
social pixel
admin+
stored xss
unfiltered html
multisite set up

5.3 Medium

AI Score

Confidence

High

Description The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PoC

1. Go to: https://example.com/wp-admin/options-general.php?page=social-pixel 2. Under โ€œFacebookโ€ add the payload '); alert(2); console.log('blah for the โ€œIdentificadorโ€. 3. Click the checkbox next to โ€œActivaciรณnโ€ 4. Save the settings and view the site to see the XSS

5.3 Medium

AI Score

Confidence

High

Related for WPVDB-ID:02CA09F8-4080-4969-992D-0E6AFB29BC62