Lucene search

K
wpvulndbLana CodesWPVDB-ID:AC7158C5-3D11-4865-B26F-41AB5A8120AF
HistoryNov 22, 2022 - 12:00 a.m.

Easy Video Player < 1.2.2.3 - Contributor+ Stored XSS

2022-11-2200:00:00
Lana Codes
wpscan.com
7
video player
cross-site scripting
contributor role
unsanitized parameters
security issue

EPSS

0.001

Percentile

25.1%

The plugin does not sanitize and escapes some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

PoC

1. Add a new post and add the payload there: [evp_embed_video url=‘" onerror=alert(/XSS/) "’] 2. Preview the post, and the XSS will trigger.

EPSS

0.001

Percentile

25.1%

Related for WPVDB-ID:AC7158C5-3D11-4865-B26F-41AB5A8120AF