WordPress Plugin Vulnerabilities
FoodBakery < 2.2 - Reflected Cross-Site Scripting (XSS)
Description
The plugin, used in the theme did not properly sanitize the foodbakery_radius parameter before outputting it back in the response, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.
Proof of Concept
Affects Plugins
Affects Themes
References
CVE
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Truoc Phan - Techlab Corporation
Submitter
Truoc Phan
Submitter website
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2021-06-14 (about 4 years ago)
Added
2021-06-14 (about 4 years ago)
Last Updated
2021-06-25 (about 4 years ago)