WordPress 的“断链检查器”(Broken Link Checker)插件在所有版本(包括 2.4.13 及之前版本)中,由于输入过滤不足和输出转义不当,存在存储型跨站脚本(Stored Cross-Site Scripting)漏洞,影响范围涵盖“评论作者 URL”和“链接日志”。 该漏洞允许未经身份验证的攻击者向将执行脚本的页面注入任意 Web 脚本,只要用户访问了被注入的页面,这些脚本就会执行。 利用此漏洞需要管理员执行插件标准的“忽略并重新检查”工作流,针对攻击者通过 WordPress 评论作者
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wpmudev | Broken Link Checker | 0 ~ 2.4.13 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet