WordPress 的 WPForms Pro 插件存在存储型跨站脚本(Stored XSS)漏洞。该漏洞存在于所有 2.0.0.2 及以下版本中,原因在于对用户输入的“单行文本”和“段落文本”字段值缺乏足够的输入清理和输出转义。这使得未认证的攻击者能够在页面中注入任意 Web 脚本,当用户访问被植入脚本的页面时,这些脚本便会执行。 该利用过程依赖于插件自身使用的 过滤器,该过滤器将 安全过滤器的白名单放宽,允许包含 属性的 元素。由于 属性不在 WordPress 的 URI 属性清理列表内,因此存储在 中的 协
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| WPForms | WPForms Pro | ≤ 2.0.0.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WPForms | WPForms Pro | 0 ~ 2.0.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet