PT-2021-15867 · Cartflows · The Funnel Builder By Cartflows
M0Ze
+1
·
Published
2021-06-01
·
Updated
2023-08-09
·
CVE-2021-24330
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Funnel Builder by CartFlows – Create High Converting Sales Funnels For WordPress plugin versions prior to 1.6.13
Description
The issue concerns the plugin's failure to sanitize its
facebook pixel id and google analytics id settings, allowing high-privilege users to set XSS payload in them. This can lead to the execution of the payload on pages generated by the plugin or the whole website, depending on the settings used.Recommendations
For versions prior to 1.6.13, update to version 1.6.13 or later to resolve the issue. As a temporary workaround, consider restricting access to the
facebook pixel id and google analytics id settings to prevent high-privilege users from setting XSS payloads.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Funnel Builder By Cartflows