WordPress 的 HUSKY – Products Filter Professional for WooCommerce 插件在 1.4.3 版本及更早版本中,存在通过 SEO 友好的永久链接(permalink)过滤 URL 片段引发的反射型跨站脚本(Reflected Cross-Site Scripting, XSS)漏洞。 该漏洞源于 函数中缺乏充分的输入净化和输出转义。该函数通过 扩展的 从 URL 路径中读取过滤值,并使用 将其嵌入到内联 JavaScript 字符串中,但未对单引号进行转义。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| realmag777 | HUSKY – Products Filter for WooCommerce Professional | 0 ~ 1.4.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet