CVE-2023-1122 | Stored Cross-Site Scripting

Опубликовано: 23 Март 2026
на канале: InfoSecHac
525
13

#cve #bug #bugbounty #bugbountytips #security #secret #research
CVE-2023-1122 is an XSS vulnerability that affects the WordPress plugin "Giveaways". The vulnerability allows attackers to inject malicious scripts into the plugin's settings pages, potentially compromising the website and its users. The vulnerability is caused by insufficient input validation and filtering in the plugin's code, which allows attackers to craft malicious scripts that are executed when users view the affected pages. This type of attack can lead to data theft, credential harvesting, and other serious consequences. To mitigate the risk, users of the "Giveaways" plugin should update to the latest version, which contains a fix for the vulnerability, and ensure that their WordPress installations are always kept up to date.

For more information :
https://wpscan.com/vulnerability/71f5...

Security Researcher :
https://twitter.com/Varun84485100?t=B...

Subscribe to our new #youtubechannel to learn #bugbounty & to watch bug PoC of live Web Applications.

If anyone wants to upload their PoC on our channel kindly contact us on LinkedIn or by mail.

Mail Id: [email protected]

"Education Purpose Only"