
PoC von CVE-2023-29439
Dieses Repository behandelt eine XSS-Sicherheitslücke im WordPress-Foogallery-Plugin.
In Foogallery 2.2.35 und früher ist die Funktion foogallery_image_editor_modal in foogallery/includes/admin/class-gallery-attachment-modal.php anfällig für XSS-Angriffe.
http://localhost:8080/wp-admin/post-new.php?post_type=foogallery&post=”><script>alert(1)</script>