Exploits / Vulnerability Discovered : 2021-06-09 |
Type : webapps |
Platform : php
This exploit / vulnerability Wordpress plugin visitorsapp 0.3 useragent stored crosssite scripting (xss) is for educational purposes only and if it is used you will do on your own risk!
## Description:
# A vulnerability in the Wordpress plugin "visitors" version 0.3 and prior allows remote attacker through
# Cross-Site Scripting (XSS) to redirect administrators and visitors and potentially obtain sensitive informations
# The 'user-agent' parameter allows attacker to escalate their privileges.