Lucene search

K
wpvulndbDmitrii IgnatyevWPVDB-ID:EA2A8420-4B0E-4EFB-A0C6-CEEA996DAE5A
HistoryMar 25, 2024 - 12:00 a.m.

Responsive Tabs < 4.0.7 - Contributor+ Stored XSS

2024-03-2500:00:00
Dmitrii Ignatyev
wpscan.com
4
stored xss
contributor role
responsive tabs

5.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Description The plugin does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PoC

1. Go to “Tab Sets > Add New” in WP Admin 2. Add a new tab and fill out values. 3. Intercept the request and for the tabs_color parameter, add the payload "+onmouseover='alert(1)'" 4. Send the request and then preview the tab group to see the XSS

CPENameOperatorVersion
eq4.0.7

5.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Related for WPVDB-ID:EA2A8420-4B0E-4EFB-A0C6-CEEA996DAE5A