WordPress 的 “Unlimited Elements For Elementor” 插件存在反射型跨站脚本(Reflected Cross-Site Scripting, XSS)漏洞,影响版本为 2.0.16 及之前所有版本,根本原因在于输入数据未经过充分的净化(sanitization),且输出时未进行适当的 HTML 转义(escaping)。 具体而言: 漏洞位于 参数处。 未认证的攻击者若能诱骗用户点击特定链接,便可在页面中注入任意 Web 脚本,而这些脚本将会被执行。 触发该漏洞的 AJAX
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| unitecms | Unlimited Elements For Elementor | 0 ~ 2.0.16 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet