# GeekyBot <=1.1.7 存储型XSS漏洞
## 概述
WordPress插件 GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation 在所有版本至 1.1.7(含)中存在存储型跨站脚本漏洞。
## 影响版本
1.1.7 及之前所有版本。
## 细节
漏洞源于聊天消息字段对输入内容缺乏充分的过滤和输出转义,导致攻击者可在页面中注入恶意脚本。
## 影响
未经身份验证的攻击者可提交恶意脚本,当管理员访问“聊天记录”页面时触发执行,从而窃取管理员会话或执行任意操作。
是否为 Web 类漏洞: 未知
判断理由:
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
标题: ERROR: The request could not be satisfied -- 🔗来源链接
标签:
神龙速读:
- **HTTP Status**: 403 ERROR
- **Error Message**: The request could not be satisfied.
- **Issue Details**: Request blocked. Connection to the server for the app or website is currently not possible. Likely due to excessive traffic or a configuration error.
- **Possible Actions**: Retry later or contact the app or website owner.
- **Additional Info for Website Owners**: Review CloudFront documentation for troubleshooting steps and error prevention.
- **Request ID**: zQN4qDvus5PebbLL2K0jM1DbugiBxkYZ5LPcVTVqekOGlFX6HwAvRA==
- **Generated By**: cloudfront (CloudFront)
标题: GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation – WordPress plugin | WordPress.org -- 🔗来源链接
标签:
神龙速读:
- **Plugin Status**: The plugin "geeky-bot" has been closed as of January 12, 2026, and is not available for download. The closure is temporary, pending a full review.
Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.