Lucene search

K
wpvulndbVishnupriya ilangoWPVDB-ID:8EDB11BC-9E8D-4A98-8538-AAFF0F072109
HistoryJun 21, 2022 - 12:00 a.m.

Brizy Page Builder < 2.4.2 - Contributor+ Stored Cross-Site Scripting via Element Content

2022-06-2100:00:00
Vishnupriya ilango
wpscan.com
8
brizy page builder
stored cross-site scripting
contributor
element content
poc
cross-site scripting
software

EPSS

0.001

Percentile

21.4%

The plugin does not sanitise and escape some element content, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

PoC

As a contributor or above, create a post using Brizy editor and: - Add a Text Element then put the following payload: - Add an Embed Element and put the following payload as embed data: The XSS will be triggered when viewing/previewing the post (for example when an admin reviews it)

EPSS

0.001

Percentile

21.4%

Related for WPVDB-ID:8EDB11BC-9E8D-4A98-8538-AAFF0F072109