Detects 'Cross-Site Scripting (XSS)' vulnerability in Paid Memberships Pro plugin for WordPress affects v. before 2.6.6.


10 sec

Domain, Ipv4

The vulnerability stems from the plugin's failure to properly escape user inputs before incorporating them into the output within an admin page. This oversight allows for the execution of malicious scripts in the context of a logged-in user's session.

Specifically, the issue occurs on the discount codes admin page of the Paid Memberships Pro plugin. The 's' parameter is not correctly sanitized before being echoed back, enabling attackers to inject malicious scripts that can be executed in the browser of any admin visiting the crafted URL.

Exploitation of this vulnerability could lead to:

  • Theft of sensitive information from the admin's session.
  • Unauthorized actions being performed on the website as the admin.
  • Potential further attacks against the site or its users.

