Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Social Media Widget (social-media-widget) plugin 4.0 for WordPress contains an externally introduced modification (Trojan Horse), which allows remote attackers to force the upload of arbitrary files.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WordPress Social Media Widget 插件HTML注入漏洞
Vulnerability Description
WordPress Social Media Widget插件是用来收藏用户常用的社交网站链接和信息订阅的插件。 WordPress的Social Media Widget插件4.0版本中存在HTML注入漏洞,该漏洞源于程序未正确过滤用户提供的输入。攻击者可利用该漏洞在受影响浏览器上下文中运行攻击者提供的HTML和脚本代码,窃取基于cookie的身份认证,或控制站点呈现给用户的方式,也可能存在其他形式的攻击。
CVSS Information
N/A
Vulnerability Type
N/A