Lucene search

K
wpvulndbDmitrii IgnatyevWPVDB-ID:04B2FEBA-E009-4FCE-8539-5DFDB4300433
HistoryMay 28, 2024 - 12:00 a.m.

Simple Share Buttons Adder < 8.5.1 - Admin+ Stored XSS

2024-05-2800:00:00
Dmitrii Ignatyev
wpscan.com
1
plugin
cross-site scripting
settings
additional css
payload
high privilege users

5.7 Medium

AI Score

Confidence

High

Description The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PoC

1. Go to the plugin settings 2. In the “Additional CSS” field, enter the payload `

CPENameOperatorVersion
eq8.5.1

5.7 Medium

AI Score

Confidence

High

Related for WPVDB-ID:04B2FEBA-E009-4FCE-8539-5DFDB4300433