WordPress 插件是WordPress开源的一个应用插件。 WordPress 插件 Simple Social Media Share Buttons 中存在跨站脚本漏洞,该漏洞源于产品将共享标题设置输出到前台时未能正确过滤输入数据。攻击者可通过该漏洞执行客户端代码。以下产品及版本受到影响:Woredpress Plugin Simple Social Media Share Buttons 3.2.4 之前版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Simple Social Media Share Buttons – Social Sharing for Everyone | 3.2.4 ~ 3.2.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-24737 | Comments - wpDiscuz <= 7.3.0 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24720 | GeoDirectory < 2.1.1.3 - Authenticated Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24719 | Enfold Theme < 4.8.4 - Reflected Cross-Site Scripting (XSS) | |
| CVE-2021-24712 | Appointment Hour Booking – WordPress Booking Plugin < 1.3.17 - Authenticated Stored XSS | |
| CVE-2021-24711 | Software License Manager < 4.5.1 - Arbitrary Domain Deletion via CSRF | |
| CVE-2021-24709 | Weather Effect < 1.3.6 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24691 | Quiz And Survey Master < 7.3.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24690 | Chained Quiz < 1.2.7.2 - Authenticated Stored Cross Site Scripting | |
| CVE-2021-24683 | Weather Effect < 1.3.4 - CSRF to Stored Cross-Site Scripting | |
| CVE-2021-24681 | Duplicate Page <= 4.4.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24651 | Poll Maker < 3.4.2 - Unauthenticated Time Based SQL Injection | |
| CVE-2021-24577 | Coming Soon and Maintenance Mode < 3.5.3 - Authenticated Stored XSS | |
| CVE-2021-24576 | Easy Accordion < 2.0.22 - Authenticated Stored XSS | |
| CVE-2021-24563 | Frontend Uploader <= 1.3.2 - Unauthenticated Stored Cross-Site Scripting | |
| CVE-2021-24546 | EditorsKit < 1.31.6 - Contributor+ Arbitrary PHP Code Execution | |
| CVE-2021-24545 | WP HTML Author Bio <= 1.2.0 - Author+ Stored Cross-Site Scripting |
No comments yet