WordPress 的 Customer Reviews for WooCommerce 插件存在存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞,受影响版本为 5.106.0 及以下。该漏洞源于对用户提供的评论文本输入缺乏充分的输入净化和输出转义。 具体而言,该插件通过名为 'cr_local_forms_submit' 的 AJAX 接口接受未经身份验证的用户提交评论,但未对包含的 HTML 内容进行净化处理,便通过 将其存入数据库。随后,在渲染产品页面时,插件通过 输出这
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ivole | Customer Reviews for WooCommerce | ≤ 5.106.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ivole | Customer Reviews for WooCommerce | 0 ~ 5.106.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet