WordPress 的 Fancy Product Designer 插件存在存储型跨站脚本漏洞,影响所有 6.5.2 及更早版本。该漏洞是由于对输入 sanitization 不足以及输出转义不够完善所导致。攻击者可以通过 Shortcode Order 中的 参数注入任意 Web 脚本,这些脚本会在任何用户访问被注入的页面时执行。具体来说,当处理存储订单 JSON 中的 字段时,注入的恶意代码会通过 innerHTML 写入 DOM(在 beforeElementAdd JavaScript 事件处理器中),因
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| radykal | Fancy Product Designer | ≤ 6.5.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| radykal | Fancy Product Designer | 0 ~ 6.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84279 | 7.2 HIGH | Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via 'output_ |
| CVE-2026-84281 | 7.2 HIGH | Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via 'product |
No comments yet