Sploitus

Exploit for WBW Currency Switcher for WooCommerce < 1.6.6 - Admin+ Stored XSS

wpexploit Β· 2022-08-22

Exploit Code

MARKDOWN4 lines
## https://sploitus.com/exploit?id=WPEX-ID:E934AF78-9DFD-4E14-853D-DC453DE6E365
In the plugin's settings (WooCommerce > Settings > Currency > Frontend Switcher), tick "Enable switcher" and put the following payload in the "Panel header text" settings: <img src onerror=alert(/XSS/)>

Save the settings. The XSS will be triggered when viewing the settings page again, as well as in any frontend page