WordPress 的 WP Composer – The Easiest Page Builder 插件(所有版本,包括 1.0.5 及更早版本)存在存储型跨站脚本(Stored XSS)漏洞。漏洞源于 'pbwp_raw_shortcode' 短代码处理程序在解码 Base64 编码的内容后,未进行任何净化或转义就直接输出。这使得拥有 Contributor(贡献者)及以上权限的已认证攻击者能够将任意 Web 脚本注入到页面中,当用户访问被注入的页面时,这些脚本将会执行。由于 Base64 编码后的字符串不包含
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ghozylab | WP Composer – The Easiest Page Builder | ≤ 1.0.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ghozylab | WP Composer – The Easiest Page Builder | 0 ~ 1.0.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet