WordPress 的 CMB2 插件存在存储型跨站脚本漏洞,该漏洞位于所有不超过 2.13.1 版本中,具体出现在 '<textarea_code 字段 ID>'(例如 kl_code、kl_post_code)参数中,原因是输入清理不足和输出转义不够完善。这使得未经身份验证的攻击者能够在网页中注入任意 Web 脚本,当用户访问被注入的页面时,这些脚本就会执行。前端保存路径仅需一个 CMB2 框的 nonce(一次性令牌),而该 nonce 通过简单的 GET 请求向所有访问者(包括未经身份验证的访客)公开,因此
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jtsternberg | CMB2 | ≤ 2.13.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jtsternberg | CMB2 | 0 ~ 2.13.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet