Jeg Kit for Elementor 是一款功能强大的 Elementor 插件,为 WordPress 提供附加组件、小部件和模板。在 3.2.19 及更早版本中,该插件存在存储型跨站脚本攻击(Stored Cross-Site Scripting, XSS)漏洞,原因在于对评论输入缺乏充分的清理和输出转义。这导致未认证的攻击者可以在页面中注入任意的 Web 脚本,当其他用户访问包含被注入脚本的页面时,脚本便会自动执行。 此外,如果攻击者使用拥有一个或多个已审核评论邮箱地址提交评论,则可实现无需管理员审核的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jegtheme | Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress | 0 ~ 3.2.19 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet