Exploits / Vulnerability Discovered : 2022-04-19 |
Type : webapps |
Platform : php
This exploit / vulnerability Wordpress plugin popup maker 1.16.5 stored crosssite scripting (authenticated) is for educational purposes only and if it is used you will do on your own risk!
1. Description:
----------------------
WordPress Plugin Popup Maker <1.16.5 does not sanitise and escape some of its popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
2. Proof of Concept:
----------------------
Create Popup > Popup Settings > Triggers > Add New Cookie > Add > Cookie Time (overwrite the default '1 month' with XSS payload)
Click 'Add' what triggers the XSS payload