In Donorbox WordPress plugin, one can perform an XSS attack via the included shortcode by inserting arbitrary HTML attributes. This vulnerability was introduced in v7.1 and fixed in v7.1.2.
[donate url='/\?\" autofocus onfocus=\"alert(window)\" abitraryAttributeToValidateShortcodeParsing=\"']
Sybre Waaijer
Sybre Waaijer
No
2019-12-31 (about 3 years ago)
2019-12-31 (about 3 years ago)
2020-01-01 (about 3 years ago)