Back to directory
WRITEUP #4188

[CVE-2019-17674 & CVE-2020-11025] Stored XSS through navigation menu item edited in Customizer in Wordpress (Write Up)

XSSStored XSS
by@evanricafort(Evan Ricafort)
Bounty
600
Program
WordPress
Published
Dec 6, 2020
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://blog.evanricafort.com/2020/12/cve-2019-17674-wordpress-stored-xss.html
RELATED WRITEUPS
Stored XSS in LibreOffice
XSSStored XSS
Persistent XSS on Microsoft Bing.com by poisoning Bingbot indexing
XSSStored XSS
Canary Token OSS Security Audit Report (Q2 2024)
XSSDoS
Type confusion attacks in ProseMirror editors
XSSType confusion
Self-XSS to ATO via Site Features
XSSSelf-XSS

Built with ❤️ by Shubham Rawat