WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 WordPress plugin WordPress Events Calendar 1.4.5之前版本存在跨站脚本漏洞,该漏洞源于在将参数输出回页面之前不会对其进行清理和转义。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| Unknown | WordPress Events Calendar Plugin | 0 ~ 1.4.5 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | WordPress Events Calendar plugin before 1.4.5 contains multiple cross-site scripting vulnerabilities. The plugin does not sanitize and escape a parameter before outputting it back in the page. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site, which can allow the attacker to steal cookie-based authentication credentials and launch other attacks. This vulnerability can be used against both unauthenticated and authenticated users. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-4320.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2022-4544 | WordPress plugin MashShare 跨站脚本漏洞 | |
| CVE-2022-4478 | WordPress plugin Font Awesome 跨站脚本漏洞 | |
| CVE-2022-4482 | WordPress plugin Carousel、Slider、Gallery 跨站脚本漏洞 | |
| CVE-2022-4549 | WordPress plugin Tickera 跨站请求伪造漏洞 | |
| CVE-2022-4508 | WordPress plugin ConvertKit 跨站脚本漏洞 | |
| CVE-2022-4477 | WordPress plugin Smash Balloon Social Post Feed 跨站脚本漏洞 | |
| CVE-2022-4476 | WordPress plugin Download Manager 跨站脚本漏洞 | |
| CVE-2022-4460 | WordPress plugin Sidebar Widgets by CodeLights 跨站脚本漏洞 | |
| CVE-2022-4483 | WordPress plugin Insert Pages 跨站脚本漏洞 | |
| CVE-2022-4060 | WordPress plugin User Post Gallery 代码注入漏洞 | |
| CVE-2022-4481 | WordPress plugin Mesmerize Companion 跨站脚本漏洞 | |
| CVE-2022-4451 | WordPress plugin Social Sharing 跨站脚本漏洞 | |
| CVE-2022-4447 | WordPress plugin Fontsy SQL注入漏洞 | |
| CVE-2022-4484 | WordPress plugin Social Share、Social Login和Social Comments 跨站脚本漏洞 | |
| CVE-2022-4578 | WordPress plugin Video Conferencing with Zoom 跨站脚本漏洞 | |
| CVE-2022-4295 | WordPress plugin Show All Comments 跨站脚本漏洞 | |
| CVE-2022-4309 | WordPress plugin Subscribe2 跨站请求伪造漏洞 | |
| CVE-2022-4431 | WordPress plugin WOOCS 跨站脚本漏洞 | |
| CVE-2022-4299 | WordPress plugin Metricool 跨站脚本漏洞 | |
| CVE-2022-2658 | WordPress plugin Spell Check 跨站脚本漏洞 |
显示前 20 条,共 41 条。 查看全部 → →
暂无评论