Lucene search

K
wpvulndbWpvulndbWPVDB-ID:749D0F25-460D-4998-AAE7-FB2246F6FA53
HistorySep 28, 2022 - 12:00 a.m.

Store Locator < 1.4.6 - Stored XSS via CSRF

2022-09-2800:00:00
wpscan.com
11
plugin csrf check missing sanitisation attacker xss payloads logged in admin software

EPSS

0.001

Percentile

20.9%

The plugin does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

EPSS

0.001

Percentile

20.9%

Related for WPVDB-ID:749D0F25-460D-4998-AAE7-FB2246F6FA53