Description
WordPress Plugin AAWP 3.16 contains a reflected cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by manipulating the tab parameter. Attackers can craft URLs with XSS payloads in the tab parameter of the aawp-settings admin page to execute arbitrary JavaScript in the context of authenticated users.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
Andrea Bocchetti
References
www.exploit-db.com/exploits/50643 (ExploitDB-50643)
getaawp.com/ (Official Product Homepage)
www.vulncheck.com/...in-aawp-reflected-xss-via-tab-parameter (VulnCheck Advisory: WordPress Plugin AAWP 3.16 Reflected XSS via tab Parameter)