
PoC of CVE-2023-29439
Ce dépôt concerne une vulnérabilité XSS dans le plugin Foogallery de WordPress.
Dans Foogallery 2.2.35 et versions antérieures, la fonction foogallery_image_editor_modal dans foogallery/includes/admin/class-gallery-attachment-modal.php est vulnérable à une attaque XSS.
http://localhost:8080/wp-admin/post-new.php?post_type=foogallery&post=”><script>alert(1)</script>