Lucene search

K
wpvulndbKrzysztof ZającWPVDB-ID:071A2F69-9CD6-42A8-A56C-264A589784AB
HistoryApr 06, 2022 - 12:00 a.m.

Content Egg < 5.3.0 - Reflected Cross-Site Scripting

2022-04-0600:00:00
Krzysztof Zając
wpscan.com
9
content egg
v5.3.0
reflected cross-site scripting
plugin
autoblogging admin dashboard

EPSS

0.001

Percentile

40.2%

The plugin does not sanitise and escape the page parameter before outputting back in an attribute in the Autoblogging admin dashboard, leading to a Reflected Cross-Site Scripting

PoC

EPSS

0.001

Percentile

40.2%

Related for WPVDB-ID:071A2F69-9CD6-42A8-A56C-264A589784AB