漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Stop Spammers Security < 2021.18 - Authenticated Stored XSS
Vulnerability Description
The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2021.18 does not escape some of its settings, allowing high privilege users such as admin to set Cross-Site Scripting payloads in them even when the unfiltered_html capability is disallowed
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
WordPress 插件跨站脚本漏洞
Vulnerability Description
WordPress是WordPress(Wordpress)基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。 Wordpress Plugin Stop Spammers Security 中存在跨站脚本漏洞,该漏洞源于产品unfiltered_html被禁止时autofocus onfocus=未对用户输入数据做有效验证。攻击者可通过该漏洞执行客户端代码。以下产品及版本受到影响:Wordpress Plugin Stop Spammers Securi
CVSS Information
N/A
Vulnerability Type
N/A