Exploit/Advisories
Published on December 6th, 2023 📆 | 3248 Views ⚑
0WordPress Phlox-Pro Theme 5.14.0 Cross Site Scripting – Torchsec
# Exploit Title: WordPress Theme phlox-pro 5.14.0 - 'searchform' Cross-Site Scripting (XSS)
# Date: 3/12/2023
# Exploit Author: Haktrak Team
# Vendor Homepage: https://phlox.pro
# Software Link: https://www.phlox.pro/go/
# Version: 5.14.0
# Tested on: Linux[apache]/wordrepss 6.3.1
# Date: 3/12/2023
# Exploit Author: Haktrak Team
# Vendor Homepage: https://phlox.pro
# Software Link: https://www.phlox.pro/go/
# Version: 5.14.0
# Tested on: Linux[apache]/wordrepss 6.3.1
Description:
A Cross Site Scripting (XSS) vulnerability exists in WordPress Theme phlox-pro
Vulnerable Code:
Steps to exploit:
1) Go to searchform
2) Insert your payload in the "search"
Proof of concept (Poc):
The following payload will allow you to run the javascript -
https://example.com/?s=ok&%27>123=1
Gloss