geotargetingwp WordPress 插件在 3.5.6.2 版本之前,未对 AJAX 响应中反射的多个参数进行清洗或转义,且这些响应以 HTML 内容类型返回。这使得未认证的攻击者能够注入任意的 Web 脚本,当受害者被诱骗提交特制的请求时,这些脚本将会被执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | geotargetingwp | 0 ~ 3.5.6.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81660 | Groundhogg < 4.5.13 - Unauthenticated Stored XSS via Web Form Dropdown/Radio Field | |
| CVE-2026-81766 | Really Simple Security < 9.8.0 - Multisite Subsite Admin+ Arbitrary Plugin Installation vi | |
| CVE-2026-78364 | MW WP Form < 5.1.6 - Editor+ Stored XSS via Inquiry Data List | |
| CVE-2026-19722 | WPvivid Backup & Migration < 0.9.133 - Admin+ Arbitrary File Write via Zip Slip in Backup | |
| CVE-2026-76585 | Customer Reviews for WooCommerce < 5.118.0 - Unauthenticated Stored XSS via 'comment' Para | |
| CVE-2026-14835 | SOGO Add Script to Individual Pages Header Footer <= 3.9 - Contributor+ Stored XSS via Pos |
No comments yet