Lucene search

K
wpvulndbFayçal CHENAWPVDB-ID:E1724471-26BD-4CB3-A279-51783102ED0C
HistoryJul 26, 2022 - 12:00 a.m.

Coming Soon - Under Construction <= 1.2.0 - Admin+ Stored Cross-Site Scripting

2022-07-2600:00:00
Fayçal CHENA
wpscan.com
27
plugin
cross-site scripting
admin
frontend
vulnerability

EPSS

0.001

Percentile

24.8%

The plugin does not sanitize and escape some of its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

PoC

As admin, put the following payload in the “More text information” settings of the plugin: The XSS will be triggered in the frontend when in Coming Soon Mode

EPSS

0.001

Percentile

24.8%

Related for WPVDB-ID:E1724471-26BD-4CB3-A279-51783102ED0C