Lucene search

K
wpvulndbSwapnil bodekarWPVDB-ID:DC2CE546-9DA1-442C-8EE2-CD660634501F
HistoryAug 02, 2021 - 12:00 a.m.

SMS Alert Order Notifications – WooCommerce < 3.4.7 Authenticated Cross Site Scripting

2021-08-0200:00:00
swapnil bodekar
wpscan.com
10

0.001 Low

EPSS

Percentile

37.5%

The plugin is affected by a cross site scripting (XSS) vulnerability in the plugin’s setting page.

PoC

Enter the payload below for the “SMS Alert Username” in the plugin’s settings. “+onfocus=“alert(1)”+autofocus=” You will observe that the JavaScript payload successfully got reflected is and we are getting a pop-up.

CPENameOperatorVersion
sms-alertlt3.4.7

0.001 Low

EPSS

Percentile

37.5%

Related for WPVDB-ID:DC2CE546-9DA1-442C-8EE2-CD660634501F