WordPress 的 LiteSpeed Cache 插件在所有版本(包括 7.8.1 及更早版本)中,由于输入清理和输出转义不足,存在存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞。这使得未经身份验证的攻击者能够在页面中注入任意 Web 脚本,当用户访问被注入的页面时,这些脚本会被执行。 攻击载荷完全由十进制数字字符引用(例如 、 、 )组成,并放置在允许的元素(如 )内部,从而绕过了 WordPress 的 清理机制。原因是 不会将文本内容中的 子字符串视为 HTML
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| litespeedtech | LiteSpeed Cache | ≤ 7.8.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| litespeedtech | LiteSpeed Cache | 0 ~ 7.8.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet