SOGO Add Script to Individual Pages Header Footer WordPress 插件(版本 ≤ 3.9)未对其从帖子元数据框中保存的自定义页眉/页脚脚本值进行清理或转义,也未将执行权限限制为拥有 能力的用户。这导致具有贡献者(contributor)及以上权限的用户可以存储 JavaScript 代码,这些代码会在任何审阅该帖子的管理员的浏览器中执行,并且在帖子发布后,也将在所有访问者的浏览器中执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | SOGO Add Script to Individual Pages Header Footer | 0 ~ 3.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81660 | Groundhogg < 4.5.13 - Unauthenticated Stored XSS via Web Form Dropdown/Radio Field | |
| CVE-2026-81766 | Really Simple Security < 9.8.0 - Multisite Subsite Admin+ Arbitrary Plugin Installation vi | |
| CVE-2026-78364 | MW WP Form < 5.1.6 - Editor+ Stored XSS via Inquiry Data List | |
| CVE-2026-19722 | WPvivid Backup & Migration < 0.9.133 - Admin+ Arbitrary File Write via Zip Slip in Backup | |
| CVE-2026-76585 | Customer Reviews for WooCommerce < 5.118.0 - Unauthenticated Stored XSS via 'comment' Para | |
| CVE-2026-14307 | Geotargeting WP < 3.5.6.2 - Reflected XSS |
No comments yet