The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/admin-ajax.php.
References
Link Resource
https://risataim.blogspot.com/2018/09/xss-en-plugin-userpro-de-wordpress.html Exploit Technical Description Third Party Advisory
https://wpvulndb.com/vulnerabilities/9124 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-09-06T23:00:00

Updated: 2018-09-08T09:57:01

Reserved: 2018-08-31T00:00:00


Link: CVE-2018-16285

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-09-06T23:29:01.210

Modified: 2018-11-02T21:33:47.707


Link: CVE-2018-16285

JSON object: View

cve-icon Redhat Information

No data.

CWE