WordPress 缓存插件 WP Fastest Cache 在所有 1.5.0 及以下版本中存在存储型跨站脚本漏洞(Stored Cross-Site Scripting, XSS),该漏洞源于对 HTTP Host 头部输入缺乏充分的净化和输出转义。攻击者无需认证即可将恶意 Web 脚本注入页面,当其他用户访问被注入的页面时,这些脚本将会被执行。 此漏洞的利用需要同时满足以下条件:必须启用 Polylang 或 Polylang Pro 插件,并且必须开启“Combine JS”(合并 JavaScript)
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| emrevona | WP Fastest Cache – WordPress Cache Plugin | 0 ~ 1.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet