###################### # Exploit Title : Wordpress Vertical image slider CSRF/XSS # Exploit Author: Ashiyane Digital Security Team # Vendor Homepage: https://wordpress.org/plugins/wp-vertical-image-slider/ # Software Link: https://downloads.wordpress.org/plugin/wp-vertical-image-slider.zip # Date: 2015-08-2 # Version: 1.0 # Tested On : Elementary OS - Firefox ###################### # Vulnerabilities : - Cross Site Request Forgery (For change the values and upload shell) - Cross Site Scripting ###################### # Vulnerable Code: ... # it shows the content of imagetitle and imageurl parameter without any filters. ###################### # Exploit (CSRF, XSS): -->