WP Fastest Cache WordPress 插件在 1.5.1 版本之前存在安全漏洞。该插件在使用 Host 头构建其所缓存页面中嵌入的资源文件 URL 时,未对 Host 头进行验证,并且未将该头信息纳入缓存键中。这使得未经身份验证的攻击者能够通过注入指向其控制的服务器的引用,来毒化缓存页面,从而导致后续所有访问者在浏览这些页面时执行任意 JavaScript 代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | WP Fastest Cache | 0.9.0.3< 1.5.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WP Fastest Cache | 0.9.0.3 ~ 1.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet