WordPress Plugin Vulnerabilities

404 SEO Redirection <= 1.3 - Reflected Cross-Site Scripting (XSS)

Description

The tab parameter of the settings page of the plugin is vulnerable to a reflected Cross-Site Scripting (XSS) issue as user input is not properly sanitised or escaped before being output in an attribute.

Proof of Concept

The PoC will be displayed once the issue has been remediated.

Affects Plugins

References

YouTube Video

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
m0ze
Verified
Yes

Timeline

Publicly Published
2021-04-16 (about 2 years ago)
Added
2021-04-27 (about 2 years ago)
Last Updated
2021-05-18 (about 2 years ago)

Other