WordPress 插件“Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates”(支持超过 700 种图案、58 个区块和模板的古腾堡编辑器及全站点编辑页面构建器插件)存在存储型跨站脚本(Stored XSS)漏洞。该漏洞存在于所有 2.2.16 及更早版本中,原因是插件对 区块属性的输入清理和输出转义处理不足。 此漏洞使得具备贡献者(contributor)及以上权限的认证攻击
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| cozythemes | Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates | ≤ 2.2.16 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cozythemes | Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates | 0 ~ 2.2.16 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet