WordPress 插件 HivePress – Business Directory, Listings & Classified Ads Plugin 在 1.7.31 及更早版本中存在存储型跨站脚本(Stored XSS)漏洞,漏洞源于对参数 的输入 sanitization(清洗)和输出 escaping(转义)不足。该漏洞允许未认证的攻击者在页面中注入任意 Web 脚本,当其他用户访问被注入的页面时,脚本将自动执行。 利用此漏洞需满足以下两个前提条件,二者均属于该插件标准且文档中支持的配置: 1. 管理员
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| hivepress | HivePress – Business Directory, Listings & Classified Ads Plugin | ≤ 1.7.31 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| hivepress | HivePress – Business Directory, Listings & Classified Ads Plugin | 0 ~ 1.7.31 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet