WordPress 的 WPBakery Page Builder 插件存在存储型跨站脚本(Stored Cross-Site Scripting)漏洞,影响版本包括 8.7.4 及更早的所有版本。该漏洞是由于对 “data” 参数的输入清洗和输出转义不足所致。这使得拥有订阅者权限或更高权限的已认证攻击者能够向页面注入任意 Web 脚本,这些脚本将在用户访问被注入的页面时执行。在保存阶段应用的 清洗无法中和攻击载荷,因为恶意脚本内容以纯字母数字文本形式进行 base64 编码,不含任何可被移除的 HTML 标签;随
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wpbakery | WPBakery Page Builder | 0 ~ 8.7.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet