Lucene search

K
wpvulndbWpvulndbWPVDB-ID:B6E40BCE-4769-41EC-9E86-64B5BFD6B171
HistoryJan 03, 2024 - 12:00 a.m.

OMGF < 5.7.10 - Unauthenticated Directory Deletion & Stored XSS

2024-01-0300:00:00
wpscan.com
5
omgf plugin
unauthenticated modification
stored xss
directory deletion
admin_init hook

6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.8%

Description The plugin is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting due to a missing capability check on the update_settings() function hooked via admin_init. This makes it possible for unauthenticated attackers to update the plugin’s settings which can be used to inject Cross-Site Scripting payloads and delete entire directories.

CPENameOperatorVersion
eq5.7.10

6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.8%

Related for WPVDB-ID:B6E40BCE-4769-41EC-9E86-64B5BFD6B171