Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it allows for injecting malicious code into a pop-up window. Successful exploitation grants an attacker with a right to execute malicious code on the administrator's computer through Excel functions as the plugin does not sanitize the user's input and allows insertion of any text.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WordPress Hustle插件注入漏洞
Vulnerability Description
WordPress是WordPress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。Hustle (又名wordpress-popup) plugin是是使用在其中的一个在线营销插件。 WordPress Hustle插件6.0.7版本中存在CSV注入漏洞,该漏洞源于程序没有过滤用户的输入。攻击者可通过向弹出窗口注入恶意代码利用该漏洞执行恶意代码。
CVSS Information
N/A
Vulnerability Type
N/A