WordPress 的 Download Monitor 插件在所有 5.2.10 及以下版本中,存在存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞。该漏洞源于对输入 sanitization(清理)和输出转义处理不足,允许攻击者通过跨域的 postMessage 通信,向管理员编辑器注入任意网页脚本。一旦用户访问被注入的页面,恶意脚本便会自动执行。 攻击者需诱导已认证的管理员访问一个由攻击者控制的页面,该页面会针对已开放的下载编辑界面发起跨域 postMessage 请求。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wpchill | Download Monitor | ≤ 5.2.10 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wpchill | Download Monitor | 0 ~ 5.2.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet