WordPress Plugin Vulnerabilities
404 SEO Redirection <= 1.3 - Reflected Cross-Site Scripting (XSS)
Description
The tab parameter of the settings page of the plugin is vulnerable to a reflected Cross-Site Scripting (XSS) issue as user input is not properly sanitised or escaped before being output in an attribute.
Proof of Concept
The PoC will be displayed once the issue has been remediated.
Affects Plugins
References
CVE
YouTube Video
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
m0ze
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2021-04-16 (about 2 years ago)
Added
2021-04-27 (about 2 years ago)
Last Updated
2021-05-18 (about 2 years ago)