WordPress 插件是WordPress开源的一个应用插件。 WordPress 插件 Frontend Uploader 1.3.2之前版本存在跨站脚本漏洞,该漏洞源于插件并不阻止HTML文件的上传,例如允许未经认证的用户上传包含JavaScript的恶意HTML文件,当有人直接访问该文件时将触发恶意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Frontend Uploader | 1.3.2 ~ 1.3.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The plugin does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly | https://github.com/V35HR4J/CVE-2021-24563 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-24737 | Comments - wpDiscuz <= 7.3.0 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24720 | GeoDirectory < 2.1.1.3 - Authenticated Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24719 | Enfold Theme < 4.8.4 - Reflected Cross-Site Scripting (XSS) | |
| CVE-2021-24712 | Appointment Hour Booking – WordPress Booking Plugin < 1.3.17 - Authenticated Stored XSS | |
| CVE-2021-24711 | Software License Manager < 4.5.1 - Arbitrary Domain Deletion via CSRF | |
| CVE-2021-24709 | Weather Effect < 1.3.6 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24691 | Quiz And Survey Master < 7.3.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24690 | Chained Quiz < 1.2.7.2 - Authenticated Stored Cross Site Scripting | |
| CVE-2021-24683 | Weather Effect < 1.3.4 - CSRF to Stored Cross-Site Scripting | |
| CVE-2021-24681 | Duplicate Page <= 4.4.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24656 | Simple Social Media Share Buttons < 3.2.4 - Authenticated Stored Cross-Site Scripting | |
| CVE-2021-24651 | Poll Maker < 3.4.2 - Unauthenticated Time Based SQL Injection | |
| CVE-2021-24577 | Coming Soon and Maintenance Mode < 3.5.3 - Authenticated Stored XSS | |
| CVE-2021-24576 | Easy Accordion < 2.0.22 - Authenticated Stored XSS | |
| CVE-2021-24546 | EditorsKit < 1.31.6 - Contributor+ Arbitrary PHP Code Execution | |
| CVE-2021-24545 | WP HTML Author Bio <= 1.2.0 - Author+ Stored Cross-Site Scripting |
No comments yet