Lucene search

K
wpvulndbWpvulndbWPVDB-ID:8F510B8C-B97A-44C9-A36D-2D775A4F7B81
HistoryMar 29, 2023 - 12:00 a.m.

Easy Forms for MailChimp < 6.8.8 - Reflected XSS

2023-03-2900:00:00
wpscan.com
11
mailchimp
plugin
xss
vulnerability
admin
parameters
response
webpage
attack

0.001 Low

EPSS

Percentile

31.2%

The plugin does not sanitise and escape some parameters before outputting them back in the response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PoC

Make a logged in admin open a page with the following code (this requires the attacker to know/guess a list_id)

0.001 Low

EPSS

Percentile

31.2%

Related for WPVDB-ID:8F510B8C-B97A-44C9-A36D-2D775A4F7B81