Themes Vulnerabilities
Zoner < 4.2 - Persistent XSS & IDOR
Description
----[]- Persistent XSS: -[]----
'Address' input field on the 'Local information' block is vulnerable so you can use your payload to steal admin cookies or do some redirects etc.
----[]- IDOR: -[]----
POST request https://zoner.fruitfulcode.com/wp-admin/admin-ajax.php?action=delete_property_act&property_id=XXX&security=YYY (where XXX is page or post ID and YYY is account security code) will delete any page or post you want.
Proof of Concept
Affects Themes
References
Classification
Type
XSS
OWASP top 10
CWE
Miscellaneous
Original Researcher
m0ze
Submitter
m0ze
Submitter twitter
Verified
No
WPVDB ID
Timeline
Publicly Published
2019-09-27 (about 6 years ago)
Added
2019-11-03 (about 6 years ago)
Last Updated
2021-01-19 (about 5 years ago)