WordPress 的 tagDiv Composer 插件在所有 5.4.5 及以下版本中存在漏洞,攻击者可通过 短代码实现存储型跨站脚本攻击(Stored Cross-Site Scripting, XSS)。该漏洞源于 方法中输入 sanitization(净化)和输出转义(escaping)措施不足。该方法在保存时会对短代码内容进行 base64 解码:由于保存前经过 处理,而编码后的负载不包含 HTML 标签,因此该过滤机制可被绕过;解码后的内容随后被直接拼接至页面 HTML 中。 由于 WordPres
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| tagDiv | tagDiv Composer | ≤ 5.4.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tagDiv | tagDiv Composer | 0 ~ 5.4.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet