脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
Unlimited Elements for Elementor < 2.0.11 - Unauthenticated Stored XSS via Google Reviews Widget
脆弱性説明
The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a malicious review on the targeted business's Google listing to deliver Stored XSS to any visitor (including administrators) of any WP page displaying that Place ID's reviews.
CVSS情報
N/A
脆弱性タイプ
N/A
脆弱性タイトル
WordPress Unlimited Elements For Elementor 跨站脚本漏洞
脆弱性説明
WordPress Unlimited Elements For Elementor是WordPress基金会的一款开发模板与组件集合的综合工具。 WordPress Unlimited Elements For Elementor 2.0.11之前版本存在跨站脚本漏洞,该漏洞源于未对从Serp API获取的Google评论内容进行清理和转义,可能导致未经身份验证的攻击者在目标企业的Google列表上提交恶意评论,从而对显示该Place ID评论的任何WordPress页面的访问者(包括管理员)发起存储型
CVSS情報
N/A
脆弱性タイプ
N/A