WordPress Seraphinite Accelerator是WordPress基金会开源的一款能提高网站响应速度的插件。 WordPress Seraphinite Accelerator 2.29.15及之前版本存在跨站脚本漏洞,该漏洞源于'seraph_accel_prep'参数使用PHP松散比较运算符绕过HMAC签名检查,且_CbContentFinishSkip()函数输出转义不足,容易受到反射型跨站脚本攻击,可能导致未经身份验证的攻击者在页面中注入恶意脚本。
| 厂商 | 产品 | 版本范围 | 状态 |
|---|---|---|---|
| seraphinitesoft | Seraphinite Accelerator | ≤ 2.29.18 |
affected |
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| seraphinitesoft | Seraphinite Accelerator | 0 ~ 2.29.18 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | The Seraphinite Accelerator plugin for WordPress up to and including 2.29.18 was vulnerable to reflected cross-site scripting through the seraph_accel_prep parameter. CacheExtractPreparePageParams() compared the expected HMAC against the JSON-decoded nonce with PHP's loose != operator, so a JSON boolean true satisfied the comparison and bypassed the signature check, and _CbContentFinishSkip() then concatenated the attacker-controlled selfTest field straight into the response body, letting unauthenticated attackers inject arbitrary scripts. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-17532.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC暂无评论