Lucene search

K
wpvulndbAsif Nawaz MinhasWPVDB-ID:365C09A7-0B10-4145-A415-5C0E9F429AE0
HistoryOct 13, 2021 - 12:00 a.m.

Testimonial Builder < 1.6.0 - Admin+ Stored Cross-Site Scripting

2021-10-1300:00:00
Asif Nawaz Minhas
wpscan.com
5

0.001 Low

EPSS

Percentile

21.6%

The plugin does not escape some testimonial fields which could allow high privilege users to perform Cross Site Scripting attacks even when the unfiltered_html capability is disallowed

PoC

As admin, create/edit a testimonial and put the following payload in the Testimonial User Name field: " style=animation-name:rotation onanimationstart=alert(/XSS/)//

CPENameOperatorVersion
testimonial-builderlt1.6.0

0.001 Low

EPSS

Percentile

21.6%

Related for WPVDB-ID:365C09A7-0B10-4145-A415-5C0E9F429AE0