Sign inSign up

ads3853/wordpress-duplicate-page-xss

By ads3853

•Updated over 3 years ago

Known Vulnerable Wordpress Plugin Image

Image
0

924

ads3853/wordpress-duplicate-page-xss repository overview

The purpose of this docker image is to test a stored XSS vulnerability in the Duplicate Page 4.4.1 plugin for Wordpress. To do this:

1. Start the Image
2. Navigate to the page, and follow the prompts, including adding a database
    - When testing for myself, I just added a mysql database docker image to my docker-compose file.
3. Once you have everything set up and are on the admin page, navigate to the Plugins tab on the left
4. Click the Activate button under the Duplicate Page plugin. DO NOT update the plugin, and any prompts that show up should be skipped.
5. Once it has been activated, you can exploit the vulnerability! More info on that on the Exploit DB page.

Link to Exploit-DB page: https://www.exploit-db.com/exploits/50256⁠

Tag summary

Content type

Image

Digest

sha256:61533ba29…

Size

221.6 MB

Last updated

over 3 years ago

docker pull ads3853/wordpress-duplicate-page-xss