Lucene search

K
wpvulndbAsif Nawaz MinhasWPVDB-ID:72AEA0E5-1FA7-4827-A173-59982202D323
HistoryAug 09, 2021 - 12:00 a.m.

Site Reviews < 5.13.1 - Authenticated Stored XSS

2021-08-0900:00:00
Asif Nawaz Minhas
wpscan.com
12
authenticated stored xss
review details
cross-site scripting
admin dashboard
payload
name/ip address
reviews list table
security
vulnerability
wordpress plugin

EPSS

0.001

Percentile

24.8%

The plugin does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed

PoC

As an admin, create a review via the Admin dashboard (/wp-admin/post-new.php?post_type=site-review) and add the following payload in the Name/IP Address fields of the Review Details section: The XSS will be triggered when viewing the Reviews list table in the admin dashboard

EPSS

0.001

Percentile

24.8%

Related for WPVDB-ID:72AEA0E5-1FA7-4827-A173-59982202D323