Exploits / Vulnerability Discovered : 2019-09-09 |
Type : webapps |
Platform : php
This exploit / vulnerability Wordpress plugin sell downloads 1.0.86 crosssite scripting is for educational purposes only and if it is used you will do on your own risk!
# PoC:
1- Go to "Products for Sale" section
2- Click on "Add New"
3- In opend window click on "Add Comment"
4- Fill comment as "/><img src=x onerror="alert()"> or "/><input type="text" onclick="alert()">
5- Click on "Publish" (or "Update" if you editing an existing product)
6- You will see a pop-up (also if click on input), Also if you go to product link will see the pop-up.