Security
Headlines
HeadlinesLatestCVEs

Headline

WordPress Circle Progress 1.0 Cross Site Scripting

WordPress Circle Progress plugin version 1.0 suffers from a persistent cross site scripting vulnerability.

Packet Storm
#xss#vulnerability#wordpress#auth#firefox
# Exploit Title: WordPress Plugin Circle progress bar – Cross sitescripting-Stored# Date: 2-06-2023# Exploit Author: Taliya Bilal- NightHawk# Vendor Homepage: https://wordpress.org/plugins/circle-progress-bar/# Version: 1.0# Tested on: Firefox# Contact me: [email protected]# Steps to reproduce:1.  Install Circle progress bar and activate plugin.2.  Navigate to Circle progress bar plugin.3.  Fill the title field with xss payload <img src=x onerror=alert(1)>4.  Click the option preview post. Here the popup will appear.#Screenshot:https://freeimage.host/i/Hrbmskvhttps://freeimage.host/i/Hrbmy4n

Packet Storm: Latest News

Acronis Cyber Protect/Backup Remote Code Execution