Embed Google Photos album WordPress 插件(版本 2.2.1 及之前版本)在将短代码属性值输出到 HTML 属性中之前,未进行适当的转义处理,导致拥有“贡献者”或更高权限的用户可以注入任意 JavaScript 代码。任何查看受影响帖子的用户(包括管理员)的浏览器都会执行这些恶意脚本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Embed Google Photos album | ≤ 2.2.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Embed Google Photos album | 0 ~ 2.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15205 | Paymob for WooCommerce < 4.1.9 - Unauthenticated SQL Injection via Paymob Callback Pixel L | |
| CVE-2026-16739 | Epeken All Kurir <= 2.1.4 - Unauthenticated Order Payment Confirmation Forgery | |
| CVE-2026-18039 | Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom P |
No comments yet