WordPress 插件 “Themify – WooCommerce Product Filter” 存在反射型跨站脚本(Reflected Cross-Site Scripting)漏洞,受影响版本为 1.5.5 及之前所有版本。该漏洞源于对查询参数名的输入过滤不足以及输出时未进行转义。这使得未经身份验证的攻击者能够通过诱导用户点击恶意链接或执行其他操作,在相应页面中注入并执行任意 Web 脚本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| themifyme | Themify – WooCommerce Product Filter | ≤ 1.5.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| themifyme | Themify – WooCommerce Product Filter | 0 ~ 1.5.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet