Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-14470. PoCs published by Damian Ebelties. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in the UserPro WordPress plugin (v<=4.9.32) via the 'error_description' parameter in the Instagram API success.php file. The PoC shows how arbitrary JavaScript can be injected and executed in the context of a victim's browser.
Description
cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/success.php error_description parameter.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in the UserPro WordPress plugin (v<=4.9.32) via the 'error_description' parameter in the Instagram API success.php file. The PoC shows how arbitrary JavaScript can be injected and executed in the context of a victim's browser.
Nuclei Templates (1)
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N