以下是对该漏洞描述的中文翻译: WordPress 的 QuickCal 插件存在存储型跨站脚本(Stored Cross-Site Scripting)漏洞。 漏洞详情: 受影响版本:所有 1.0.20 及之前版本。 根本原因:由于自定义字段参数缺乏足够的输入净化和输出转义,攻击者可以在页面中注入任意 Web 脚本。当用户访问被注入的页面时,这些脚本将会被执行。 非认证攻击向量:保护“未认证预约添加(booked_add_appt)”AJAX 操作的 nonce 值公开嵌入在渲染预订日历短代码的任意页面上。这意味
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Themovation | QuickCal | 0 ~ 1.0.20 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet