WordPress 插件 Speed Optimizer – The All-In-One Performance-Boosting Plugin 存在存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞,影响范围为所有等于或低于 7.8.0 的版本。该漏洞是由于输入清理和输出转义不足所致。攻击者可以通过图像标签属性注入恶意脚本,当其他用户访问被注入的页面时,这些脚本便会执行。要利用此漏洞,攻击者需要具有贡献者级别(contributor)或更高的权限,并且网站管理员必须在插件设置
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| siteground | Speed Optimizer – The All-In-One Performance-Boosting Plugin | ≤ 7.8.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siteground | Speed Optimizer – The All-In-One Performance-Boosting Plugin | 0 ~ 7.8.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet