Swaven WTB Widget — postMessage Origin Bypass PoC

Attacker origin:

indexOf(".swaven.com"): → PASSES the old wtbLoader.js check

endsWith(".swaven.com"): → new loader.js would BLOCK this


How it works: This page opens hungry-man.com/where-to-buy (a real Swaven/MikMak customer). That page natively loads the legacy wtbLoader.js which checks origin.indexOf(".swaven.com"). Our attacker origin passes that check. We send postMessage with wtb:serverTracking + arbitrary script.