### [CVE-2017-17043](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17043) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description The Emag Marketplace Connector plugin 1.0.0 for WordPress has reflected XSS because the parameter "post" to /wp-content/plugins/emag-marketplace-connector/templates/order/awb-meta-box.php is not filtered correctly. ### POC #### Reference - https://packetstormsecurity.com/files/145060/wpemagmc10-xss.txt - https://wpvulndb.com/vulnerabilities/8964 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/ARPSyndicate/kenzer-templates