Themes Vulnerabilities
Multiple Themes - Reflected XSS
Description
The themes suffer from the same issue about the search box reflecting the results causing XSS which allows an unauthenticated attacker to exploit against users if they click a malicious link.
Proof of Concept
https://example.com/?s=katana<IMG """><IMG SRC=/ onerror="alert(1)"></img>/asd/
Affects Themes
References
CVE
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Submitter
Random Robbie
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2023-08-14 (about 3 months ago)
Added
2023-08-14 (about 3 months ago)
Last Updated
2023-08-31 (about 3 months ago)