Tricks for Weaponizing XSS
ID: f3c9464e-bf89-5b3d-bdca-dbdb8e6cab38
STIX ID: report--f3c9464e-bf89-5b3d-bdca-dbdb8e6cab38
Feed Name: TrustedSec blog
Threat Score
This blog post demonstrates weaponizing a stored XSS vulnerability in WordPress to create a new administrator account: it shows hosting a remote payload, using XMLHttpRequest to fetch /wp-admin/user-new.php, parsing the _wpnonce_create-user CSRF token from the response, and submitting a crafted POST to add a user, including full example code and mitigation notes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
