Themes Vulnerabilities

Business Directory <= 1.2.0 - Unauthenticated Reflected Cross-Site Scripting (XSS)

Description

This theme does not sanitise its search input, leading to a Reflected XSS issue when output back in the search result page.

Note (WPScanTeam): The theme has been removed from the WordPress marketplace listing on March 22nd, 2021

Proof of Concept

Affects Themes

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Franciny Salles e Flavio Landivar
Submitter
franciny
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2021-03-25 (about 4 years ago)
Added
2021-03-25 (about 4 years ago)
Last Updated
2021-03-26 (about 4 years ago)

Other