WordPress是WordPress(Wordpress)基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。NextGEN Gallery是使用在其中的一个图片库插件。 WordPress plugin NextGEN Gallery Pro 3.1.11之前版本存在安全漏洞,该漏洞源于电子商务模块中,有一个调用通过photocrati ajax获取购物车物品的操作,之后设置[shipping_address][name]能够注入恶意javascript
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | NextGen Gallery Pro | 3.1.11 ~ 3.1.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-24272 | Fitness Calculators < 1.9.6 - Cross-Site Request Forgery to Cross-Site Scripting (XSS) | |
| CVE-2021-24256 | Elementor - Header, Footer & Blocks Template < 1.5.8 - Contributor+ Stored XSS | |
| CVE-2021-24255 | Essential Addons for Elementor < 4.5.4 - Contributor+ Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24264 | Image Hover Effects - Elementor Addon < 1.3.4 - Contributor+ Stored XSS | |
| CVE-2021-24263 | PowerPack Addons for Elementor < 2.3.2 - Contributor+ Stored XSS | |
| CVE-2021-24262 | WooLentor - WooCommerce Elementor Addons + Builder < 1.8.6 - Contributor+ Stored XSS | |
| CVE-2021-24261 | HT Mega - Absolute Addons for Elementor Page Builder < 1.5.7 - Contributor+ Stored XSS | |
| CVE-2021-24260 | Livemesh Addons for Elementor < 6.8 - Contributor+ Stored XSS | |
| CVE-2021-24259 | Elementor Addon Elements < 1.11.2 - Contributor+ Stored XSS | |
| CVE-2021-24257 | Premium Addons for Elementor < 4.2.8 - Contributor+ Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24254 | College Publisher Import <= 0.1 - Arbitrary File Upload to RCE | |
| CVE-2021-24271 | Ultimate Addons for Elementor < 1.30.0 - Contributor+ Stored XSS | |
| CVE-2021-24270 | DethemeKit For Elementor < 1.5.5.5 - Contributor+ Stored XSS | |
| CVE-2021-24269 | Sina Extension for Elementor < 3.3.12 - Contributor+ Stored XSS | |
| CVE-2021-24268 | JetWidgets For Elementor < 1.0.9 - Contributor+ Stored XSS | |
| CVE-2021-24267 | All-in-One Addons for Elementor - WidgetKit < 2.3.10 - Contributor+ Stored XSS | |
| CVE-2021-24266 | The Plus Addons for Elementor Page Builder Lite < 2.0.6 - Contributor+ Stored XSS | |
| CVE-2021-24265 | Rife Elementor Extensions & Templates < 1.1.6 - Contributor+ Stored XSS | |
| CVE-2021-24253 | Classyfrieds <= 3.8 - Authenticated Arbitrary File Upload to RCE | |
| CVE-2021-24252 | Event Banner <= 1.3 - Arbitrary File Upload to RCE |
No comments yet