Liquid Web / StellarWP GiveWP是Liquid Web / StellarWP的WordPress捐赠插件。 Nexcess GiveWP 4.16.1及之前版本存在跨站脚本漏洞,该漏洞源于对参数'sequoia[introduction][image]'的输入清理和输出转义不足,可能导致经过身份验证的攻击者(具有Give Worker级别及更高权限)在页面中注入任意Web脚本,当用户访问被注入的页面时会执行这些脚本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| stellarwp | GiveWP – Donation Plugin and Fundraising Platform | ≤ 4.16.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| stellarwp | GiveWP – Donation Plugin and Fundraising Platform | 0 ~ 4.16.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet