WordPress Plugin Vulnerabilities

Booking.com Product Helper < 1.0.2 - Admin+ Stored Cross-Site Scripting

Description

The plugin does not sanitize and escape Product Code when creating Product Shortcode, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Proof of Concept

When creating a "New product shortcode" you can inject XSS payloads like <--`<img/src=` onerror=confirm``> --!> in the Product Code form field. When a page that includes that product's shortcode is viewed by a visitor, the payload will execute.

Affects Plugins

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Asif Nawaz Minhas
Submitter
Asif Nawaz Minhas
Verified
Yes

Timeline

Publicly Published
2021-10-05 (about 2 years ago)
Added
2021-10-05 (about 2 years ago)
Last Updated
2023-04-12 (about 1 years ago)

Other