WordPress是Wordpress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress 插件是WordPress开源的一个应用插件。 The About Author Box WordPress plugin 1.0.2之前版本存在跨站脚本漏洞,该漏洞源于插件不会在将Social Profiles字段值输出到属性中之前对其进行清理和转义。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | About Author Box | 1.0.2 ~ 1.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-24842 | Bulk Datetime Change < 1.12 - Missing Authorisation | |
| CVE-2017-20008 | myCRED < 1.7.8 - Reflected Cross-Site Scripting | |
| CVE-2021-24748 | Email Before Download < 6.8 - Admin+ SQL Injection | |
| CVE-2021-24749 | URL Shortify < 1.5.1 - Arbitrary Link/Group Deletion via CSRF | |
| CVE-2021-24751 | GenerateBlocks < 1.4.0 - Contributor+ Stored Cross-Site Scripting | |
| CVE-2021-24755 | myCred < 2.3 - Subscriber+ SQL Injection | |
| CVE-2021-24768 | WP RSS Aggregator < 4.19.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24811 | Shop Page WP < 1.2.8 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24822 | Stylish Cost Calculator < 7.04 - Subscriber+ Unauthorised AJAX Calls to Stored XSS | |
| CVE-2021-24927 | My Calendar < 3.2.18 - Subscriber+ Reflected Cross-Site Scripting | |
| CVE-2021-24860 | BSK PDF Manager < 3.1.2 - Admin+ SQL Injection | |
| CVE-2021-24876 | Registrations for The Events Calendar < 2.7.5 - Reflected Cross-Site Scripting | |
| CVE-2021-24883 | Popup Anything < 2.0.4 - Contributor+ Stored Cross-Site Scripting | |
| CVE-2021-24889 | Ninja Forms < 3.6.4 - Admin+ SQL Injection | |
| CVE-2021-24899 | Media-Tags <= 3.2.0.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24908 | Check & Log Email < 1.0.4 - Reflected Cross-Site Scripting | |
| CVE-2021-24915 | Contest Gallery < 13.1.0.6 - Missing Access Controls to Unauthenticated SQL injection / Em | |
| CVE-2021-24918 | Smash Balloon Social Post Feed < 4.0.1 - Subscriber+ Arbitrary Plugin Settings Update to S |
No comments yet