Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Breeze Cache < 2.5.6 - Unauthenticated Stored XSS via Minify Library
Vulnerability Description
The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WordPress Breeze Cache 跨站脚本漏洞
Vulnerability Description
cloudways Breeze Cache是cloudways的消息队列中间件。 WordPress Breeze Cache 2.5.6之前版本存在跨站脚本漏洞,该漏洞源于HTML压缩过程中使用可预测的替换哈希且滥用正则表达式,可能导致未经身份验证的攻击者通过预测占位符格式在最终HTML输出中注入任意HTML属性,造成存储型跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A