WordPress 插件 WPForms – AI Form Builder for WordPress(包含联系表单、支付表单、调查表单、测验等功能)的所有版本(包括 2.0.2.1 及更早版本)中存在反射型跨站脚本(Reflected Cross-Site Scripting, XSS)漏洞。该漏洞源于插件在 “attacker-chosen key referenced by the smart tag (e.g. 'x')” 参数中缺乏充分的输入过滤和输出转义处理。 攻击者无需身份认证即可将恶意脚本注入到网
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| smub | WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More | ≤ 2.0.2.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| smub | WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More | 0 ~ 2.0.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet