WordPress 的 Fancy Product Designer 插件(所有 6.5.2 及更早版本)在 '_fpd_data' 订单项元数据中的 'productTitle' 字段存在存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞。该漏洞是由于输入清理和输出转义不足所导致,攻击者无需认证即可在页面中注入任意网页脚本。当用户访问包含恶意脚本的页面时,这些脚本便会自动执行。 攻击者可通过向未注册用户开放的 AJAX 操作 (通过 注册)发送恶意数据,该操作未进行 nonce
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| radykal | Fancy Product Designer | ≤ 6.5.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| radykal | Fancy Product Designer | 0 ~ 6.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84279 | 7.2 HIGH | Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via 'output_ |
| CVE-2026-84280 | 7.2 HIGH | Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via Shortcod |
No comments yet