WordPress Plugin Vulnerabilities
Contact Form by Supsystic < 1.7.20 - Admin+ Stored Cross-Site Scripting
Description
The plugin does not sanitise and escape fields label, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
Proof of Concept
Create/edit a field in a form, and put the following payload in the label: <img src=x onerror=alert(/XSS/)>
Affects Plugins
References
Exploitdb
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Murat DEMIRCI
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2021-10-28 (about 2 years ago)
Added
2021-10-28 (about 2 years ago)
Last Updated
2022-04-08 (about 1 years ago)