WordPress Plugin Vulnerabilities

Advanced AJAX Product Filters < 1.5.4.7 - Unauthenticated Reflected Cross-Site Scripting (XSS)

Description

The br_aapf_get_child AJAX action of the plugin, available to both unauthenticated and authenticated users does not sanitise the 'term_id' POST parameter before outputting it in the page, leading to reflected Cross-Site Scripting issue.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
dc11
Submitter
dc11
Verified
Yes

Timeline

Publicly Published
2021-06-09 (about 4 years ago)
Added
2021-06-17 (about 4 years ago)
Last Updated
2021-06-25 (about 4 years ago)

Other