Lucene search

K
wpvulndbIohexWPVDB-ID:8EC76242-717D-4D2D-9C0F-3056CD7C2C90
HistoryNov 30, 2022 - 12:00 a.m.

Paytium < 4.3.7 - Admin+ Stored XSS

2022-11-3000:00:00
iohex
wpscan.com
7
paytium
xss
stored cross-site scripting

0.001 Low

EPSS

Percentile

23.3%

The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PoC

1. Go to Playtium ยป Settings and in the โ€˜Testโ€™ mode, add the payload to both โ€˜Live API Keyโ€™ and โ€˜Test API Keyโ€™. The payload is: โ€œ><โ€ 2. Save the changes and go to Playtium ยป Setup wizard to see the XSS popup.

CPENameOperatorVersion
paytiumlt4.3.7

0.001 Low

EPSS

Percentile

23.3%

Related for WPVDB-ID:8EC76242-717D-4D2D-9C0F-3056CD7C2C90