
WordPress Plugin HTML Author Bio description XSS
This is an XSS vulnerability discovered in a plugin that is no longer distributed as a plugin.
WordPress Plugin HTML Author Bio description XSS
This vulnerability is caused by improper validation of the description parameter in /wp-admin/profile.php.
A remote attacker can exploit this by sending a maliciously crafted HTTP request.
When installing, please configure port forwarding in the docker-compose.yml file.
$ docker-compose up
Navigate to http://[web-server ip]:port/.
Proceed with the basic installation.
Install the plugin using the WP-HTML-Author-Bio-master.zip file.
Go to the following path:
http://[web-server ip]:port/wp-admin/profile.php
Insert an XSS payload using an img tag into the Biographical Info field.

Then, when you go to the WordPress blog, you can see the XSS executed as shown in the image below.

https://wpscan.com/vulnerability/64267134-9d8c-4e0c-b24f-d18692a5775e