[CVE-2023-5757] How I found Stored XSS from 100K+ downloaded plugin
Back in October 2023, I was working on finding vulnerabilities in WordPress plugins. Among one of them, I found a vulnerability from WP Crowdfunding which had a 100K + download. It was a Stored XSS vulnerability that occurs in WP Crowdfunding version <= 2.1.8. What is WP Crowdfunding? WP Crowdfunding is a plugin that enables.