WordPress 反垃圾邮件插件 Anti-Spam by CleanTalk – Spam Protection Without CAPTCHA 存在存储型跨站脚本漏洞(Stored Cross-Site Scripting, XSS)。该漏洞影响 6.88 及更早版本,原因是插件对 'comment' 参数缺乏充分的输入净化和输出转义。 此漏洞允许未经身份验证的攻击者在网站页面中注入任意 Web 脚本,当其他用户访问被注入恶意脚本的页面时,脚本将会自动执行。只要攻击者发送的评论被审核通过,该漏洞即可被利用。在
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cleantalk | Anti-Spam by CleanTalk – Spam Protection Without CAPTCHA | 0 ~ 6.88 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet