WordPress是Wordpress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是WordPress开源的一个应用插件。 WordPress plugin advanced-booking-calendar 1.7.1 之前版本存在跨站脚本漏洞,该漏洞源于在将房间参数输出回管理页面之前不会对其进行清理和转义,从而导致反射跨站点脚本问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Advanced Booking Calendar | 1.7.1 ~ 1.7.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WordPress Advanced Booking Calendar plugin before 1.7.1 contains a cross-site scripting vulnerability. It does not sanitize and escape the room parameter before outputting it back in an admin page. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1007.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-0828 | Download Manager < 3.2.39 - Unauthenticated brute force of files master key | |
| CVE-2021-24986 | Post Grid < 2.1.16 - Reflected Cross-Site Scripting via keyword | |
| CVE-2021-24987 | Super Socializer < 7.13.30 - Reflected Cross-Site Scripting | |
| CVE-2021-25090 | GridKit Portfolio < 2.1.0 - Subscriber+ Stored Cross-Site Scripting | |
| CVE-2022-0246 | iQ Block Country < 1.2.13 - Admin+ Arbitrary File Deletion via Zip Slip | |
| CVE-2022-0271 | LearnPress < 4.1.6 - Reflected Cross-Site Scripting | |
| CVE-2022-0314 | Nimble Page Builder < 3.2.2 - Reflected Cross-Site Scripting | |
| CVE-2022-0447 | Post Grid < 2.1.16 - Reflected Cross-Site Scripting via post_types | |
| CVE-2022-0471 | Favicon by RealFaviconGenerator < 1.3.23 - Reflected Cross-Site Scripting | |
| CVE-2022-0531 | WPvivid Backup and Migration Plugin < 0.9.70 - Reflected Cross-Site Scripting | |
| CVE-2022-0728 | Easy Smooth Scroll Links < 2.23.1 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-1023 | Podcast Importer SecondLine < 1.3.8 - Admin+ SQLi | |
| CVE-2022-0840 | Easy Social Icons < 3.2.1 - Admin+ Stored Cross-Site Scripting in add icon | |
| CVE-2022-0892 | Export All URLs < 4.2 - Reflected Cross-Site Scripting | |
| CVE-2022-0914 | Export All URLs < 4.3 - Private/Draft Post/Page Title Disclosure via CSRF | |
| CVE-2022-0919 | Salon booking system < 7.6.3 - Unauthenticated Sensitive Data Disclosure | |
| CVE-2022-0920 | Salon booking system < 7.6.3 - Customer+ Bookings/Customers Data Disclosure | |
| CVE-2022-0949 | WP Block and Stop Bad Bots < 6.930 - Unauthenticated SQLi | |
| CVE-2022-0969 | Image optimization & Lazy Load < 3.3.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-0989 | NS WooCommerce Watermark <= 2.11.3 - Abuse of Functionality |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet