The plugins do not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Create new Testimonial, add the following payload to either Position or Testimonial Text field: "></textarea><img src onerror=alert(/XSS/)> Publish it, the payload will be triggered in the backend (in the Testimonial list, and when editing the related testimonial), and in page/posts where the shortcode is embed
Asif Nawaz Minhas
Asif Nawaz Minhas
Yes
2022-10-20 (about 3 months ago)
2022-10-20 (about 3 months ago)
2022-10-20 (about 3 months ago)