WordPress 的 WP2Social Auto Publish 插件存在存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞,受影响版本为 2.4.12 及更早版本。该漏洞源于输入数据未充分过滤、输出未充分转义,体现在管理端设置中。 这意味着,拥有管理员级别或更高权限的认证攻击者,可以向页面中注入任意 Web 脚本;当用户访问这些被注入的页面时,脚本会被执行。此漏洞仅影响多站点(multi-site)安装,以及已禁用 unfiltered_html 权限的安装环境。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| f1logic | WP2Social Auto Publish | 0 ~ 2.4.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet