WordPress 插件“Frontend Admin by DynamiApps”存在存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞,该漏洞在 3.28.36 及以下所有版本中均存在。此问题是由于插件中的 函数在未使用 HTML 感知解析(HTML-aware parsing)的情况下,对帖子内容执行了文本级别的查找和替换操作,从而导致可通过绕过 kses 安全过滤机制或利用变异型 XSS(Mutation XSS)注入恶意脚本。该漏洞允许拥有贡献者(Contributor
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| shabti | Frontend Admin by DynamiApps | ≤ 3.28.36 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| shabti | Frontend Admin by DynamiApps | 0 ~ 3.28.36 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet