Lucene search

K
wpvulndb0x23.soWPVDB-ID:1F41FC5C-18D0-493D-9A7D-8B521AB49F85
HistoryMay 04, 2022 - 12:00 a.m.

Poll Maker < 4.0.2 - Admin+ Stored Cross-Site Scripting

2022-05-0400:00:00
0x23.so
wpscan.com
8
plugin vulnerability
user privilege escalation
cross-site scripting
unsanitized input
mailchimp integration

EPSS

0.001

Percentile

24.8%

The plugin does not sanitise and escape some settings, which could allow high privilege users such as admin to perform Store Cross-Site Scripting attack even when unfiltered_html is disallowed

PoC

Put the following payload in any of the Mailchimp integration settings (/wp-admin/admin.php?page=poll-maker-ays-settings&ays;_poll_tab=tab2) and save: ">

EPSS

0.001

Percentile

24.8%

Related for WPVDB-ID:1F41FC5C-18D0-493D-9A7D-8B521AB49F85