Lucene search

K
wpvulndbApple502jWPVDB-ID:25A28ADB-794F-4BDB-89E8-060296B45B38
HistoryJan 12, 2022 - 12:00 a.m.

Remove Footer Credit < 1.0.11 - Admin+ Stored Cross-Site Scripting

2022-01-1200:00:00
apple502j
wpscan.com
10
security
sanitization
cross-site scripting
privilege escalation
plugin
settings
xss
software

EPSS

0.001

Percentile

21.4%

The plugin does properly sanitise its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

PoC

In the plugin’s settings, put the following values: - In “Step 1: Enter text/HTML to remove (one per line)” field: powered - In “Step 2: Enter your own footer credit (one per line)”: ">–> The XSS will be triggered in all pages

EPSS

0.001

Percentile

21.4%

Related for WPVDB-ID:25A28ADB-794F-4BDB-89E8-060296B45B38