CVE-2018-19564
MEDIUMEasy Testimonials 3.2 - Stored Cross-Site Scripting via _ikcf_client, _ikcf_position, and _ikcf_other Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-19564. PoCs published by En_dust.
AI-analyzed exploit summary This is a proof-of-concept for a stored XSS vulnerability in the WordPress plugin Easy Testimonials 3.2. The exploit demonstrates how malicious scripts can be injected into three parameters (_ikcf_client, _ikcf_position, _ikcf_other) via a POST request to the WordPress admin panel.
Description
Stored XSS was discovered in the Easy Testimonials plugin 3.2 for WordPress. Three wp-admin/post.php parameters (_ikcf_client and _ikcf_position and _ikcf_other) have Cross-Site Scripting.
Exploits (1)
This is a proof-of-concept for a stored XSS vulnerability in the WordPress plugin Easy Testimonials 3.2. The exploit demonstrates how malicious scripts can be injected into three parameters (_ikcf_client, _ikcf_position, _ikcf_other) via a POST request to the WordPress admin panel.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N