[-] Title : wordpress hashtagger plugin - 3.2 -Cross-Site-Scripting
[-] Author : Abolfazl Feyz
[-] Vendor : https://github.com/wp-plugins/hashtagger
[-] Dork : inurl: /plugins/hashtagger-master/
[-] Date : 11.January.2021
------------------------------------
Vulnerable page:
wordpress/wp-content/plugins/hashtagger-master/hashtagger.php
------------------------------------
---------------------------------------------------
Vulnerable source:
420: $url = admin_url('options-general.php?page=' . $_GET['page'] . '&tab=');
432: echo echo $url . 'general';
----------------------------------------------------
--------------------------------------------------------
POC :
http://site.com/wp-content/plugins/hashtagger-master/hashtagger.php?url=[XSS]
======================================
= cantact me =
= Telegram ==> Mr_ramkal =
= instagram ==> aboolfazl_feyz =
= email ==> khodebolfazl@gmail.com =
======================================