WordPress是Wordpress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是WordPress开源的一个应用插件。 Wordpress plugin Post Grid 2.1.16 版本之前存在跨站脚本漏洞,该漏洞源于在将关键字参数输出回属性之前不会对其进行转义,从而导致在包含带有搜索表单的 Post Grid 的页面中出现反射型跨站脚本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-0840 | Easy Social Icons < 3.2.1 - Admin+ Stored Cross-Site Scripting in add icon | |
| CVE-2021-24987 | Super Socializer < 7.13.30 - Reflected Cross-Site Scripting | |
| CVE-2021-25090 | GridKit Portfolio < 2.1.0 - Subscriber+ Stored Cross-Site Scripting | |
| CVE-2022-0246 | iQ Block Country < 1.2.13 - Admin+ Arbitrary File Deletion via Zip Slip | |
| CVE-2022-0271 | LearnPress < 4.1.6 - Reflected Cross-Site Scripting | |
| CVE-2022-0314 | Nimble Page Builder < 3.2.2 - Reflected Cross-Site Scripting | |
| CVE-2022-0447 | Post Grid < 2.1.16 - Reflected Cross-Site Scripting via post_types | |
| CVE-2022-0471 | Favicon by RealFaviconGenerator < 1.3.23 - Reflected Cross-Site Scripting | |
| CVE-2022-0531 | WPvivid Backup and Migration Plugin < 0.9.70 - Reflected Cross-Site Scripting | |
| CVE-2022-0728 | Easy Smooth Scroll Links < 2.23.1 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-0828 | Download Manager < 3.2.39 - Unauthenticated brute force of files master key | |
| CVE-2022-1023 | Podcast Importer SecondLine < 1.3.8 - Admin+ SQLi | |
| CVE-2022-0892 | Export All URLs < 4.2 - Reflected Cross-Site Scripting | |
| CVE-2022-0914 | Export All URLs < 4.3 - Private/Draft Post/Page Title Disclosure via CSRF | |
| CVE-2022-0919 | Salon booking system < 7.6.3 - Unauthenticated Sensitive Data Disclosure | |
| CVE-2022-0920 | Salon booking system < 7.6.3 - Customer+ Bookings/Customers Data Disclosure | |
| CVE-2022-0949 | WP Block and Stop Bad Bots < 6.930 - Unauthenticated SQLi | |
| CVE-2022-0969 | Image optimization & Lazy Load < 3.3.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-0989 | NS WooCommerce Watermark <= 2.11.3 - Abuse of Functionality | |
| CVE-2022-1006 | Advanced Booking Calendar < 1.7.1 - Admin+ SQLi |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet