WordPress 的 Fancy Product Designer 插件存在存储型跨站脚本漏洞(Stored Cross-Site Scripting, XSS),该漏洞存在于所有 6.5.2 及更早版本中,原因是“output_format”参数在处理时缺乏足够的输入清理和输出转义。攻击者无需认证即可在页面中注入任意 Web 脚本,当其他用户访问被植入恶意脚本的页面时,这些脚本便会自动执行。 需要注意的是,该漏洞的利用要求目标站点必须启用“Pro Export/Genius”功能,因为存在漏洞的 AJAX 操作
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| radykal | Fancy Product Designer | ≤ 6.5.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| radykal | Fancy Product Designer | 0 ~ 6.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84281 | 7.2 HIGH | Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via 'product |
| CVE-2026-84280 | 7.2 HIGH | Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via Shortcod |
No comments yet