WordPress plugin是WordPress开源的一个应用插件。 WordPress plugin Booster for WooCommerce 5.4.9之前版本存在跨站脚本漏洞,该漏洞源于。在Product XML Feeds模块启用时,插件在输出回管理仪表板之前缺少对于wcj_create_products_xml_result参数进行转义和过滤,导致了一个反射的的跨站点脚本漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Booster for WooCommerce | 5.4.9 ~ 5.4.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-24999 | Booster for Woocommerce < 5.4.9 - Reflected Cross-Site Scripting in PDF Invoicing Module | |
| CVE-2021-25040 | Booking Calendar < 8.9.2 - Reflected Cross-Site Scripting | |
| CVE-2021-25030 | Events Made Easy < 2.2.36 - Subscriber+ SQL Injection | |
| CVE-2021-25027 | PowerPack Addons for Elementor < 2.6.2 - Reflected Cross-Site Scripting | |
| CVE-2021-25023 | Speed Booster Pack < 4.3.3.1 - Admin+ SQL Injection | |
| CVE-2021-25022 | UpdraftPlus < 1.16.66 - Reflected Cross-Site Scripting | |
| CVE-2021-25021 | OMGF < 4.5.12 - Admin+ Arbitrary Folder Deletion via Path Traversal | |
| CVE-2021-25020 | CAOS < 4.1.9 - Admin+ Arbitrary Folder Deletion via Path Traversal | |
| CVE-2021-25016 | Chaty < 2.8.3 - Reflected Cross-Site Scripting | |
| CVE-2021-25000 | Booster for WooCommerce < 5.4.9 - Reflected Cross-Site Scripting in General Module | |
| CVE-2021-24680 | WP Travel Engine < 5.3.1 - Editor+ Stored Cross-Site Scripting | |
| CVE-2021-24991 | WooCommerce PDF Invoices & Packing Slips < 2.10.5 - Reflected Cross-Site Scripting | |
| CVE-2021-24973 | Site Reviews < 5.17.3 - Unauthenticated Stored Cross-Site Scripting | |
| CVE-2021-24964 | LiteSpeed Cache < 4.4.4 - IP Check Bypass to Unauthenticated Stored XSS | |
| CVE-2021-24963 | LiteSpeed Cache < 4.4.4 - Admin+ Reflected Cross-Site Scripting | |
| CVE-2021-24893 | Stars Rating < 3.5.1 - Comments Denial of Service | |
| CVE-2021-24831 | Tab - Accordion, FAQ < 1.3.2 - Unauthenticated AJAX Calls | |
| CVE-2021-24828 | Mortgage Calculator / Loan Calculator < 1.5.17 - Contributor+ Stored Cross-Site Scripting | |
| CVE-2021-24786 | Download Monitor < 4.4.5 - Admin+ SQL Injection |
No comments yet