WordPress 插件 SEOWriting 在 1.12.5 及更早版本中存在一个存储型跨站脚本(Stored XSS)漏洞。该漏洞允许已认证的投稿者(contributors)利用对 元素过于宽松的 KSES 白名单机制——该白名单明确允许 事件处理程序——来注入恶意 JavaScript 代码。攻击者可以在帖子内容中植入精心构造的 JavaScript 载荷,这些载荷会在高权限用户查看或预览受影响的帖子时执行,可能导致权限提升或账户被盗用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SEOWriting | SEOWriting | ≤ 1.12.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SEOWriting | SEOWriting | 0 ~ 1.12.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet