WordPress Plugin Vulnerabilities

Flower Delivery by Florist One <= 3.7 - Admin+ Stored Cross-Site Scripting

Description

The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setups)

Proof of Concept

As admin, go to the plugin's settings, create a new Location, put the following payload in the "Funeral Home Name" then save the location and the settings: <img src onerror=prompt(/XSS/)>

Affects Plugins

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
fuzzyap1
Submitter
fuzzyap1
Submitter website
Verified
Yes

Timeline

Publicly Published
2022-06-02 (about 1 years ago)
Added
2022-06-02 (about 1 years ago)
Last Updated
2023-05-02 (about 1 years ago)

Other