mirror of
https://github.com/0xMarcio/cve.git
synced 2026-03-27 17:30:27 +01:00
697 B
697 B
CVE-2016-10986
Description
The tweet-wheel plugin before 1.0.3.3 for WordPress has XSS via consumer_key, consumer_secret, access_token, and access_token_secret.
POC
Reference
- https://0x62626262.wordpress.com/2016/04/21/tweet-wheel-xss-vulnerability/
- https://wpvulndb.com/vulnerabilities/8464