WordPress 插件 “GiveWP – Donation Plugin and Fundraising Platform” 在所有版本(含 4.14.4 及更早版本)中,因“give_form”短代码存在存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞。其根本原因在于对短代码属性 和 的输入过滤不足且输出未正确转义:这两个属性虽经过 处理,但在输出到 HTML 数据属性(data attributes)时未进行充分的 HTML 转义。这使得拥有“贡献者(Contribut
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| stellarwp | GiveWP – Donation Plugin and Fundraising Platform | 0 ~ 4.14.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet