Lucene search

K
wpvulndbWpvulndbWPVDB-ID:CA8068F7-DCF0-44FD-841D-D02987220D79
HistoryApr 16, 2021 - 12:00 a.m.

SEO Redirection < 6.4 - Authenticated Stored Cross-Site Scripting (XSS)

2021-04-1600:00:00
wpscan.com
8

0.001 Low

EPSS

Percentile

24.8%

The plugin did not sanitise the Redirect From and Redirect To fields when creating a new redirect in the dashboard, allowing high privilege users (even with the unfiltered_html disabled) to set XSS payloads

PoC

Create a new Custom redirect (/wp-admin/options-general.php?page=seo-redirection.php) and set a payload such as /"> in the Redirect From and Redirect To fields

CPENameOperatorVersion
seo-redirectionlt6.4

0.001 Low

EPSS

Percentile

24.8%

Related for WPVDB-ID:CA8068F7-DCF0-44FD-841D-D02987220D79