WordPress是Wordpress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress 插件是WordPress开源的一个应用插件。 Wordpress Plugins 存在跨站脚本漏洞,该漏洞源于 Popup Anything 插件中对用户提供的数据的清理不足。经过身份验证的远程攻击者可以在易受攻击的网站上下文中在用户浏览器中注入和执行任意 HTML 和脚本代码。 公开的漏洞允许远程攻击者执行跨站点脚本 (XSS) 攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Popup Anything – A Marketing Popup | 2.0.4 ~ 2.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-24822 | Stylish Cost Calculator < 7.04 - Subscriber+ Unauthorised AJAX Calls to Stored XSS | |
| CVE-2017-20008 | myCRED < 1.7.8 - Reflected Cross-Site Scripting | |
| CVE-2021-24745 | About Author Box < 1.0.2 - Contributor+ Stored Cross-Site Scripting | |
| CVE-2021-24748 | Email Before Download < 6.8 - Admin+ SQL Injection | |
| CVE-2021-24749 | URL Shortify < 1.5.1 - Arbitrary Link/Group Deletion via CSRF | |
| CVE-2021-24751 | GenerateBlocks < 1.4.0 - Contributor+ Stored Cross-Site Scripting | |
| CVE-2021-24755 | myCred < 2.3 - Subscriber+ SQL Injection | |
| CVE-2021-24768 | WP RSS Aggregator < 4.19.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24811 | Shop Page WP < 1.2.8 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24927 | My Calendar < 3.2.18 - Subscriber+ Reflected Cross-Site Scripting | |
| CVE-2021-24842 | Bulk Datetime Change < 1.12 - Missing Authorisation | |
| CVE-2021-24860 | BSK PDF Manager < 3.1.2 - Admin+ SQL Injection | |
| CVE-2021-24876 | Registrations for The Events Calendar < 2.7.5 - Reflected Cross-Site Scripting | |
| CVE-2021-24889 | Ninja Forms < 3.6.4 - Admin+ SQL Injection | |
| CVE-2021-24899 | Media-Tags <= 3.2.0.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24908 | Check & Log Email < 1.0.4 - Reflected Cross-Site Scripting | |
| CVE-2021-24915 | Contest Gallery < 13.1.0.6 - Missing Access Controls to Unauthenticated SQL injection / Em | |
| CVE-2021-24918 | Smash Balloon Social Post Feed < 4.0.1 - Subscriber+ Arbitrary Plugin Settings Update to S |
No comments yet