Novel Attack Vector to Bypass CSP Via Same Origin Method Execution (Wordpress Zeroday)
pwn.ai | blog | #vulnerability-research | #wordpress | #xss | #csp-bypass | #jsonp | #same-origin-method-execution
Summary
Paulos Yibelo's technique bypasses CSP on sites hosting any WordPress endpoint, abusing the hidden _jsonp parameter and Same Origin Method Execution to turn HTML injection into full XSS.
- Published
- Collected
Skip to content