WordPress 插件 Podlove Podcast Publisher 存在存储型跨站脚本(Stored XSS)漏洞,影响所有版本至 4.5.5(含该版本)。该漏洞源于输入过滤不足及输出转义不当,具体体现在 参数中。 这意味着拥有“贡献者(contributor)”级别或更高权限的已认证攻击者,可以向页面注入任意网页脚本;当其他用户访问这些被注入的页面时,脚本将被执行。 具体技术细节如下: 贡献者评论数据被存储在插件自管理的自定义数据表中,从而绕过了 WordPress 核心的 过滤器。 钩子触发时未进行
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| eteubert | Podlove Podcast Publisher | 0 ~ 4.5.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet