Lucene search

K
wpvulndbApple502jWPVDB-ID:06DF2729-21DA-4C22-AE1E-DDA1F15BDF8F
HistoryJul 12, 2021 - 12:00 a.m.

Page View Counts < 2.4.9 - Contributor+ Stored XSS

2021-07-1200:00:00
apple502j
wpscan.com
10
page view counts
plugin
contributor
stored xss
postid parameter
xss attacks
admin
frontend
unfiltered_html capability
poc
software

EPSS

0.001

Percentile

24.8%

The plugin does not escape the postid parameter of pvc_stats shortcode, allowing users with a role as low as Contributor to perform Stored XSS attacks. A post made by a contributor would still have to be approved by an admin to have the XSS triggered in the frontend, however, higher privilege users, such as editor could exploit this without the need of approval, and even when the blog disallows the unfiltered_html capability.

PoC

[pvc_stats postid=‘a" style=“animation-name:twentytwentyone-close-button-transition” onanimationend="alert(origin)’] [pvc_stats postid=‘a" onmouseover="alert(origin)’]

EPSS

0.001

Percentile

24.8%

Related for WPVDB-ID:06DF2729-21DA-4C22-AE1E-DDA1F15BDF8F