WordPress Jeg Kit for Elementor是WordPress基金会的一款针对Elementor的页面构建组件集合。 WordPress Jeg Kit for Elementor 3.2.6及之前版本存在跨站脚本漏洞,该漏洞源于Image Box widget的'sg_body_description'参数输入清理和输出转义不足,可能导致认证攻击者(贡献者级别及以上)注入存储型跨站脚本,在用户访问页面时执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jegtheme | Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress | ≤ 3.2.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jegtheme | Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress | 0 ~ 3.2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet