Lucene search

K
wpvulndbWpvulndbWPVDB-ID:655A68EE-9447-41CA-899E-986A419FB7ED
HistoryJun 26, 2023 - 12:00 a.m.

Membership Plugin - Restrict Content < 3.2.3 - Reflected XSS

2023-06-2600:00:00
wpscan.com
6
membership
plugin
restrict content
cross-site scripting
vulnerability

EPSS

0.001

Percentile

35.8%

The plugin does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PoC

Make a logged-in admin open a page containing the HTML code below.

EPSS

0.001

Percentile

35.8%

Related for WPVDB-ID:655A68EE-9447-41CA-899E-986A419FB7ED