Lucene search

K
wpvulndbWpvulndbWPVDB-ID:23553517-34E3-40A9-A406-F3FFBE9DD265
HistoryDec 13, 2019 - 12:00 a.m.

WordPress <= 5.3 - Authenticated Stored XSS via Crafted Links

2019-12-1300:00:00
wpscan.com
21

EPSS

0.002

Percentile

64.3%

The function wp_targeted_link_rel() can be used in a particular way to result in a Stored Cross-Site Scripting (XSS) vulnerability.

PoC

This is a PoC for a Stored XSS

EPSS

0.002

Percentile

64.3%

Related for WPVDB-ID:23553517-34E3-40A9-A406-F3FFBE9DD265