WordPress 的 Beaver Builder 插件(Starter 版本)在所有版本中(包括 2.11.0.1 及更早版本)存在通过 参数中的 引发的反射型跨站脚本攻击(Reflected Cross-Site Scripting, XSS)漏洞,原因是输入验证不足且输出未正确转义。这使得未经身份验证的攻击者能够成功诱使用户执行某个操作(例如点击一个包含恶意脚本的链接),从而在网页中注入任意 Web 脚本并使其执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| The Beaver Builder Team | Beaver Builder Plugin (Starter Version) | 0 ~ 2.11.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet