WordPress 的 LiteSpeed Cache 插件存在存储型跨站脚本(Stored XSS)漏洞,受影响版本为 7.7 及更早的所有版本。该漏洞源于一个存在缺陷的正则表达式,该正则表达式在启用“Lazy Load Images”和“Add Missing Sizes”功能时,用于从图像中剥离 和 属性。这使得拥有 Author(作者)级别及以上权限的已认证攻击者,能够通过精心构造的 标签属性,在页面中注入任意 Web 脚本。当用户访问这些被注入的页面时,脚本将被执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| litespeedtech | LiteSpeed Cache | ≤ 7.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| litespeedtech | LiteSpeed Cache | 0 ~ 7.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet