The Emag Marketplace Connector plugin 1.0.0 for WordPress has reflected XSS because the parameter "post" to /wp-content/plugins/emag-marketplace-connector/templates/order/awb-meta-box.php is not filtered correctly.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://packetstormsecurity.com/files/145060/wpemagmc10-xss.txt | exploit vdb entry third party advisory |
https://wpvulndb.com/vulnerabilities/8964 | third party advisory exploit |
https://wordpress.org/support/topic/wordpress-emag-marketplace-connector-1-0-cross-site-scripting-vulnerability/ | third party advisory exploit |