Wordpress plugin cookie law bar 1.2.1 clb_bar_msg stored crosssite scripting (xss) Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2021-05-25 |
Type : webapps |
Platform : php
This exploit / vulnerability Wordpress plugin cookie law bar 1.2.1 clb_bar_msg stored crosssite scripting (xss) is for educational purposes only and if it is used you will do on your own risk!
# the "Bar Message" text field is vulnerable to stored XSS due to unsanitized user input
# an authenticated attacker can retrieve cookies / sensitive data of all Wordpress users
# proof of concept
# navigate to the settings of the Cookie Law Bar under