.. / CVE-2022-0535

Exploit for WordPress E2Pdf <1.16.45 - Cross-Site Scripting (CVE-2022-0535)

Description:

WordPress E2Pdf plugin before 1.16.45 contains a cross-site scripting vulnerability. The plugin does not sanitize and escape some of its settings, even when the unfiltered_html capability is disallowed. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site, making it possible to steal cookie-based authentication credentials and launch other attacks.

Nuclei Template

View the template here CVE-2022-0535.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-0535.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2022-0535
https://wpscan.com/vulnerability/a4162e96-a3c5-4f38-a60b-aa3ed9508985
https://mikadmin.fr/tech/XSS-Stored-E2Pdf-798ef69b0e13c36acf5446358d57c965Dx90666bNvCw98.pdf
https://wordpress.org/plugins/e2pdf/
https://plugins.trac.wordpress.org/changeset/2675049/e2pdf