Lucene search

K
wpvulndbRafael AristodimouWPVDB-ID:74613B38-48F2-43D5-BAE5-25C89BA7DB6E
HistoryOct 27, 2023 - 12:00 a.m.

Popup Box < 3.7.9 - Admin+ Stored XSS

2023-10-2700:00:00
Rafael Aristodimou
wpscan.com
7
popup box
stored xss
cross-site scripting
wordpress

EPSS

0

Percentile

14.0%

Description The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

PoC

  1. Create a new popup via /wp-admin/admin.php?page=ays-pb&action;=add 2) Set its “Custom content” and “Popup description” fields to the following: 3) Save, and notice the alert box appearing when re-editing the popup, and visiting the website.

EPSS

0

Percentile

14.0%

Related for WPVDB-ID:74613B38-48F2-43D5-BAE5-25C89BA7DB6E