Lucene search

K
wpvulndbJrXnmWPVDB-ID:0AA5A8D5-E736-4CD3-ABFD-8E0A356BB6EF
HistoryJan 03, 2022 - 12:00 a.m.

Visual CSS Style Editor < 7.5.4 - Reflected Cross-Site Scripting

2022-01-0300:00:00
JrXnm
wpscan.com
3

0.001 Low

EPSS

Percentile

30.1%

The plugin does not sanitise and escape the wyp_page_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

PoC

https://example.com/wp-admin/admin.php?page=yellow-pencil-editor&amp;href;=1&amp;wyp;_page_id=home&amp;wyp;_page_type=home&amp;wyp;_mode=single&amp;wyp;_page_type=

0.001 Low

EPSS

Percentile

30.1%

Related for WPVDB-ID:0AA5A8D5-E736-4CD3-ABFD-8E0A356BB6EF