
POC (XSS) -> CVE-2024-6651
POC (XSS) -> CVE-2024-6651
Functional PoC for vulnerability CVE-2024-6651, which affects the plugin WP File Upload < 4.24.8, allowing Reflected Cross-Site Scripting (XSS) in WordPress.
This vulnerability allows arbitrary JavaScript code injection via an unsanitized parameter in the admin panel of the WP File Upload plugin.
The attack occurs through the dir parameter in the File Browser functionality, allowing JavaScript execution in the browser of an authenticated user (typically an administrator).
⚠️ Exclusive use for educational purposes and authorized environments.
Reflected XSS
git clone https://github.com/yup-Ivan/CVE-2024-6651.git
cat payload.txt