Lucene search

K
wpvulndbJrXnmWPVDB-ID:399FFD65-F3C0-4FBE-A83A-2A620976AAD2
HistoryNov 15, 2021 - 12:00 a.m.

Pixel Cat Lite < 2.6.2 - CSRF to Stored Cross-Site Scripting

2021-11-1500:00:00
JrXnm
wpscan.com
11
pixel cat lite
csrf
stored cross-site scripting
security flaw
admin access
input sanitization

EPSS

0.001

Percentile

32.0%

The plugin does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attacker to make a logged in admin change them and perform Cross-Site Scripting attacks

PoC

EPSS

0.001

Percentile

32.0%

Related for WPVDB-ID:399FFD65-F3C0-4FBE-A83A-2A620976AAD2