WordPress 的 Avada (Fusion) Builder 插件在 3.15.6 及之前的所有版本中,由于输入净化不足和输出转义缺失,存在通过短代码 'size' 属性导致的存储型跨站脚本(Stored XSS)漏洞。这使得拥有贡献者级别及以上权限的已认证攻击者能够向页面中注入任意 Web 脚本,这些脚本将在用户访问被注入的页面时执行。由于注入的内容完全包含在短代码属性字符串中,且该字符串内不含 HTML 尖括号,因此 WordPress 的 过滤器未能中和该载荷,导致其在保存时原样通过。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| themefusion | Avada (Fusion) Builder | ≤ 3.15.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| themefusion | Avada (Fusion) Builder | 0 ~ 3.15.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet