CVE-2024-11388 poc exploit # CVE-2024-11388
CVE-2024-11388 poc exploit
The Dino Game – Embed Google Chrome Dinosaur Game in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dino-game' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
[4.0K] /data/pocs/1040c53fa8ace6e40e7b5d8560fc3b1e6f9a27d2
├── [4.0K] CVE-2024-11388
│ └── [ 219] CVE-2024-11388.txt
└── [ 543] README.md
1 directory, 2 files