.. / CVE-2018-18069

Exploit for WordPress sitepress-multilingual-cms 3.6.3 - Cross-Site Scripting (CVE-2018-18069)

Description:

WordPress plugin sitepress-multilingual-cms 3.6.3 is vulnerable to cross-site scripting in process_forms via any locale_file_name_ parameter (such as locale_file_name_en) in an authenticated theme-localization.php request to wp-admin/admin.php.

Nuclei Template

View the template here CVE-2018-18069.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2018/CVE-2018-18069.yaml
Copy

References:

https://github.com/Elsfa7-110/kenzer-templates
https://0x62626262.wordpress.com/2018/10/08/sitepress-multilingual-cms-plugin-unauthenticated-stored-xss/
https://nvd.nist.gov/vuln/detail/CVE-2018-18069
https://github.com/merlinepedra/nuclei-templates
https://github.com/ARPSyndicate/kenzer-templates