WordPress 的 WP Customer Reviews 插件在 3.7.8 及更早的所有版本中,由于对输入数据缺乏充分的清洗和输出转义,在“wpcr3_fname”参数上存在反射型跨站脚本(XSS)漏洞。这使得未认证的攻击者能够诱导用户执行某个操作(例如点击链接),从而在相应页面上注入并执行任意 Web 脚本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| bompus | WP Customer Reviews | 0 ~ 3.7.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet