WordPress 插件“用户资料构建器 – 精美的用户注册表单、用户资料与用户角色编辑器”在所有版本(包括 4.0.0 及之前版本)中,由于输入过滤不足且输出未正确转义,存在存储型跨站脚本攻击(Stored Cross-Site Scripting, XSS)漏洞,该漏洞通过 参数触发。这使得未经身份验证的攻击者能够向页面中注入任意的 Web 脚本,当用户访问被注入的页面时,这些脚本将自动执行。攻击载荷会传递至拥有 权限的管理员:当这些管理员访问“用户 > 未确认电子邮件地址”列表表格并与行操作链接进行交互时,被
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cozmoslabs | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor | 0 ~ 4.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet