WordPress 插件 Molongui Authorship – Author Boxes, Guest Authors & Co-Authors 存在存储型 DOM 跨站脚本(Stored DOM-Based Cross-Site Scripting)漏洞,该漏洞影响所有 5.2.12 及更早版本。漏洞原因是插件对输入数据的清理和输出转义处理不足。通过评论中的 href 属性(位于评论内容中)参数,未认证的攻击者可以在网页中注入任意 Web 脚本,当用户访问被注入的页面时,这些脚本将会被执行。 该漏洞在免费版
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| molongui | Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress | ≤ 5.2.12 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| molongui | Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress | 0 ~ 5.2.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet