Lucene search

K
wpvulndbApple502jWPVDB-ID:7C6C0AAC-1733-4ABC-8E95-05416636A127
HistorySep 06, 2021 - 12:00 a.m.

Bitcoin / AltCoin Payment Gateway for WooCommerce < 1.6.1 - Reflected Cross-Site Scripting

2021-09-0600:00:00
apple502j
wpscan.com
23

0.001 Low

EPSS

Percentile

43.2%

The plugin does not escape the ‘s’ GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue

PoC

https://example.com/wp-admin/admin.php?page=cs-woo-altcoin-all-coins&amp;s;=">

CPENameOperatorVersion
woo-altcoin-payment-gatewaylt1.6.1

0.001 Low

EPSS

Percentile

43.2%

Related for WPVDB-ID:7C6C0AAC-1733-4ABC-8E95-05416636A127