Lucene search

K
wpvulndbAsif Nawaz MinhasWPVDB-ID:4BDA5DFF-F577-4CD8-A225-C6B4C32F22B4
HistoryOct 04, 2021 - 12:00 a.m.

Coming Soon, Under Construction & Maintenance Mode By Dazzler < 1.6.7 - Admin+ Stored Cross-Site Scripting

2021-10-0400:00:00
Asif Nawaz Minhas
wpscan.com
5

0.001 Low

EPSS

Percentile

24.8%

The plugin does not sanitise or escape its description setting when outputting it in the frontend when the Coming Soon mode is enabled, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

PoC

Via the plugin’s settings: - Enable the ‘Coming Soon Mode’ - Put the following payload in the Description field Then access the frontend as a user to trigger the XSS

CPENameOperatorVersion
coming-soon-wplt1.6.7

0.001 Low

EPSS

Percentile

24.8%

Related for WPVDB-ID:4BDA5DFF-F577-4CD8-A225-C6B4C32F22B4