WordPress是Wordpress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是WordPress开源的一个应用插件。 WordPress 插件 WooCommerce PDF Invoices & Packing Slips 2.10.5之前版本存在跨站脚本漏洞,该漏洞源于。插件的参数在输出到属性之前,不会对标签和部分参数进行过滤和转义,导致管理仪表板上出现了一个反射的跨站脚本漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WooCommerce PDF Invoices & Packing Slips | 2.10.5 ~ 2.10.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The Wordpress plugin WooCommerce PDF Invoices & Packing Slips before 2.10.5 does not escape the tab and section parameters before reflecting it an attribute, leading to a reflected cross-site scripting in the admin dashboard. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24991.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-25000 | Booster for WooCommerce < 5.4.9 - Reflected Cross-Site Scripting in General Module | |
| CVE-2021-25040 | Booking Calendar < 8.9.2 - Reflected Cross-Site Scripting | |
| CVE-2021-25030 | Events Made Easy < 2.2.36 - Subscriber+ SQL Injection | |
| CVE-2021-25027 | PowerPack Addons for Elementor < 2.6.2 - Reflected Cross-Site Scripting | |
| CVE-2021-25023 | Speed Booster Pack < 4.3.3.1 - Admin+ SQL Injection | |
| CVE-2021-25022 | UpdraftPlus < 1.16.66 - Reflected Cross-Site Scripting | |
| CVE-2021-25021 | OMGF < 4.5.12 - Admin+ Arbitrary Folder Deletion via Path Traversal | |
| CVE-2021-25020 | CAOS < 4.1.9 - Admin+ Arbitrary Folder Deletion via Path Traversal | |
| CVE-2021-25016 | Chaty < 2.8.3 - Reflected Cross-Site Scripting | |
| CVE-2021-25001 | Booster for WooCommerce < 5.4.9 - Reflected Cross-Site Scripting in Product XML Feeds Modu | |
| CVE-2021-24680 | WP Travel Engine < 5.3.1 - Editor+ Stored Cross-Site Scripting | |
| CVE-2021-24999 | Booster for Woocommerce < 5.4.9 - Reflected Cross-Site Scripting in PDF Invoicing Module | |
| CVE-2021-24973 | Site Reviews < 5.17.3 - Unauthenticated Stored Cross-Site Scripting | |
| CVE-2021-24964 | LiteSpeed Cache < 4.4.4 - IP Check Bypass to Unauthenticated Stored XSS | |
| CVE-2021-24963 | LiteSpeed Cache < 4.4.4 - Admin+ Reflected Cross-Site Scripting | |
| CVE-2021-24893 | Stars Rating < 3.5.1 - Comments Denial of Service | |
| CVE-2021-24831 | Tab - Accordion, FAQ < 1.3.2 - Unauthenticated AJAX Calls | |
| CVE-2021-24828 | Mortgage Calculator / Loan Calculator < 1.5.17 - Contributor+ Stored Cross-Site Scripting | |
| CVE-2021-24786 | Download Monitor < 4.4.5 - Admin+ SQL Injection |
No comments yet