WordPress 插件是WordPress开源的一个应用插件。 WordPress 插件 存在代码注入漏洞,该漏洞源于 Gutenberg Block Editor Toolkit – EditorsKit 插件在 1.31.6 版本之前不清理和验证自定义可见性设置的条件逻辑,允许具有低权限用户执行任意 PHP 代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Gutenberg Block Editor Toolkit – EditorsKit | 1.31.6 ~ 1.31.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-24737 | Comments - wpDiscuz <= 7.3.0 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24720 | GeoDirectory < 2.1.1.3 - Authenticated Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24719 | Enfold Theme < 4.8.4 - Reflected Cross-Site Scripting (XSS) | |
| CVE-2021-24712 | Appointment Hour Booking – WordPress Booking Plugin < 1.3.17 - Authenticated Stored XSS | |
| CVE-2021-24711 | Software License Manager < 4.5.1 - Arbitrary Domain Deletion via CSRF | |
| CVE-2021-24709 | Weather Effect < 1.3.6 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24691 | Quiz And Survey Master < 7.3.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24690 | Chained Quiz < 1.2.7.2 - Authenticated Stored Cross Site Scripting | |
| CVE-2021-24683 | Weather Effect < 1.3.4 - CSRF to Stored Cross-Site Scripting | |
| CVE-2021-24681 | Duplicate Page <= 4.4.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24656 | Simple Social Media Share Buttons < 3.2.4 - Authenticated Stored Cross-Site Scripting | |
| CVE-2021-24651 | Poll Maker < 3.4.2 - Unauthenticated Time Based SQL Injection | |
| CVE-2021-24577 | Coming Soon and Maintenance Mode < 3.5.3 - Authenticated Stored XSS | |
| CVE-2021-24576 | Easy Accordion < 2.0.22 - Authenticated Stored XSS | |
| CVE-2021-24563 | Frontend Uploader <= 1.3.2 - Unauthenticated Stored Cross-Site Scripting | |
| CVE-2021-24545 | WP HTML Author Bio <= 1.2.0 - Author+ Stored Cross-Site Scripting |
No comments yet