Wordpress simple urls Plugin < 115 XSS

CVE Category Price Severity
CVE-2023-0099 CWE-79 $500 High
Author Risk Exploitation Type Date
Unknown High Remote 2024-02-15
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at:

Below is a copy:

Wordpress simple urls Plugin < 115 XSS
# Exploit Title: simple urls < 115  XSS
# Google Dork:
# Exploit Author: AmirZargham
# Vendor Homepage:
# Software Link:
# Version: < 115
# Tested on: firefox,chrome
# CVE: CVE-2023-0099
# CWE: CWE-79
# Platform: MULTIPLE
# Type: WebApps

The Simple URLs WordPress plugin before 115 does not sanitise and escape
some parameters before outputting them back in some pages, leading to
Reflected Cross-Site Scripting.

Usage Info:

send malicious link to victim:

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.