Lucene search

K
wpvulndbAsif Nawaz MinhasWPVDB-ID:11C89925-4FE9-45F7-9020-55FE7BBAE3DB
HistorySep 20, 2022 - 12:00 a.m.

We’re Open! < 1.42 - Admin+ Stored Cross-Site Scripting

2022-09-2000:00:00
Asif Nawaz Minhas
wpscan.com
6
plugin
vulnerability
admin+ stored cross-site scripting
settings
xss
multisite

EPSS

0.001

Percentile

24.8%

The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PoC

Put the following payload in the Settings > We’re Open > Separators & Text > Closed Text: "> Save the settings, the XSS will be triggered on pages/posts where the Closed Text is displayed, for example when [open] is embed is there is at least one closed day

EPSS

0.001

Percentile

24.8%

Related for WPVDB-ID:11C89925-4FE9-45F7-9020-55FE7BBAE3DB