Authored by AmirZargham

WordPress Simple URLs plugin versions prior to 115 suffer from a cross site scripting vulnerability.

advisories | CVE-2023-0099

# Exploit Title: simple urls < 115  XSS
# Google Dork:
# Exploit Author: AmirZargham
# Vendor Homepage:
# Software Link:
# Version: < 115
# Tested on: firefox,chrome
# CVE: CVE-2023-0099
# CWE: CWE-79
# Platform: MULTIPLE
# Type: WebApps

The Simple URLs WordPress plugin before 115 does not sanitise and escape
some parameters before outputting them back in some pages, leading to
Reflected Cross-Site Scripting.

Usage Info:

send malicious link to victim: