Lucene search

K
wpvulndbKauenavarroWPVDB-ID:6CC05A33-6592-4D35-8E66-9B6A9884DF7E
HistoryMay 14, 2024 - 12:00 a.m.

WP eMember < 10.3.9 - Reflected XSS

2024-05-1400:00:00
kauenavarro
wpscan.com
2
wordpress
emember
plugin
xss
security
vulnerability

AI Score

9.2

Confidence

High

EPSS

0

Percentile

9.0%

Description The plugin does not sanitize and escape the “fieldId” parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

PoC

https://www.example.com/wp-admin/admin-ajax.php?fieldId=&amp;action;=check_name

AI Score

9.2

Confidence

High

EPSS

0

Percentile

9.0%

Related for WPVDB-ID:6CC05A33-6592-4D35-8E66-9B6A9884DF7E