Lucene search

K
wpvulndbYuyudhnWPVDB-ID:90EBAEDC-89DF-413F-B22E-753D4DD5E1C3
HistorySep 05, 2022 - 12:00 a.m.

Slider Hero < 8.4.4 - Admin+ Stored Cross-Site Scripting

2022-09-0500:00:00
yuyudhn
wpscan.com
5
slider hero
vulnerability
stored cross-site scripting
admin+

0.001 Low

EPSS

Percentile

24.8%

The plugin does not escape the slider Name, which could allow high-privileged users to perform Cross-Site Scripting attacks.

PoC

Create or edit a Slide and put the following payload in the Name field: " onfocus=alert(/XSS/) autofocus=" The XSS will be triggered when editing the slide again

CPENameOperatorVersion
slider-herolt8.4.4

0.001 Low

EPSS

Percentile

24.8%

Related for WPVDB-ID:90EBAEDC-89DF-413F-B22E-753D4DD5E1C3