WordPress 插件是WordPress开源的一个应用插件。 WordPress 插件 WP HTML Author Bio 1.2.0之前版本存在跨站脚本漏洞,该漏洞源于软件对于用户的HTML缺少有效的验证与转义,允许他们使用恶意JavaScript代码,当任何人访问该用户在前端的帖子时,恶意代码将被执行。因此,角色低至作者的用户可以对用户执行跨站点脚本攻击,这可能导致管理员查看相关帖子时发生权限升级的情况。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WP HTML Author Bio | 1.2.0 ~ 1.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The plugin does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the frontend made by such user. As a result, user with a role as low as author could perform Cross-Site Scripting attacks against users, which could potentially lead to privilege escalation when an admin view the related post/s. | https://github.com/V35HR4J/CVE-2021-24545 | POC Details |
| 2 | WordPress Plugin HTML Author Bio description XSS | https://github.com/dnr6419/CVE-2021-24545 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-24737 | Comments - wpDiscuz <= 7.3.0 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24720 | GeoDirectory < 2.1.1.3 - Authenticated Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24719 | Enfold Theme < 4.8.4 - Reflected Cross-Site Scripting (XSS) | |
| CVE-2021-24712 | Appointment Hour Booking – WordPress Booking Plugin < 1.3.17 - Authenticated Stored XSS | |
| CVE-2021-24711 | Software License Manager < 4.5.1 - Arbitrary Domain Deletion via CSRF | |
| CVE-2021-24709 | Weather Effect < 1.3.6 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24691 | Quiz And Survey Master < 7.3.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24690 | Chained Quiz < 1.2.7.2 - Authenticated Stored Cross Site Scripting | |
| CVE-2021-24683 | Weather Effect < 1.3.4 - CSRF to Stored Cross-Site Scripting | |
| CVE-2021-24681 | Duplicate Page <= 4.4.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24656 | Simple Social Media Share Buttons < 3.2.4 - Authenticated Stored Cross-Site Scripting | |
| CVE-2021-24651 | Poll Maker < 3.4.2 - Unauthenticated Time Based SQL Injection | |
| CVE-2021-24577 | Coming Soon and Maintenance Mode < 3.5.3 - Authenticated Stored XSS | |
| CVE-2021-24576 | Easy Accordion < 2.0.22 - Authenticated Stored XSS | |
| CVE-2021-24563 | Frontend Uploader <= 1.3.2 - Unauthenticated Stored Cross-Site Scripting | |
| CVE-2021-24546 | EditorsKit < 1.31.6 - Contributor+ Arbitrary PHP Code Execution |
No comments yet