The plugin does not sanitise the "wp_group_name" parameter before outputting it back in the "Groups" page, leading to an Authenticated Stored Cross-Site Scripting issue (WPScanTeam): During the verification of the fixes with the vendor, other payloads and injection points were identified, reported and fixed
Add/edit a Group with the following name: <svg/onload=alert(/XSS/)> (WPScanTeam): Another payload (noticed when working with the vendor on the fixes) 1')" style=animation-name:rotation onanimationstart=alert(/XSS/)//
Muhammad Daffa
Muhammad Daffa
Yes
2021-07-26 (about 1 years ago)
2021-07-26 (about 1 years ago)
2022-02-24 (about 1 years ago)