WordPress 的 bbp style pack 插件存在存储型跨站脚本(Stored XSS)漏洞,影响版本为 6.4.8 及之前所有版本。该漏洞源于对 (通过 设置)和 (通过 bbPress 回复表单提交)参数的输入净化不足以及输出转义不当。 这使得拥有订阅者(subscriber)级别或更高权限的已认证攻击者能够向页面中注入任意 Web 脚本,当用户访问被注入的页面时,这些脚本将被执行。成功利用该漏洞要求攻击者将其构造的回复内容包裹在 标签块中,此举可阻止 WordPress 的 / 处理程序将存储的用
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| robin-w | bbp style pack | ≤ 6.4.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| robin-w | bbp style pack | 0 ~ 6.4.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet