WordPress 的 Responsive Plus – Elementor 模板与起始站点插件在所有不超过 3.5.3 版本的软件中,由于输入过滤和输出转义处理不足,存在通过短代码属性进行的存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞。该漏洞允许具有贡献者级别及以上访问权限的已认证攻击者在页面中注入任意 Web 脚本,每当有用户访问被注入的页面时,这些脚本便会执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| cyberchimps | Responsive Starter Templates – Elementor Templates & Starter Sites | ≤ 3.5.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cyberchimps | Responsive Starter Templates – Elementor Templates & Starter Sites | 0 ~ 3.5.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet