WordPress 插件 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 存在反射型跨站脚本(Reflected Cross-Site Scripting, XSS)漏洞。该漏洞影响所有 6.2.14 及以下版本,原因是输入 sanitization(清理)和输出转义处理不足。攻击者可以通过任何符合 占位符格式的任意参数名称(PoC 中使用了 ‘proof’ 作为参数名)注入恶意脚本。 如果
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wpmanageninja | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | ≤ 6.2.14 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wpmanageninja | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | 0 ~ 6.2.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet