适用于 WordPress 的“All in One SEO – AI SEO 插件用于提升 SEO 排名和流量(支持结构化数据、本地 SEO、网站地图及 SEO 洞察)”插件,在所有 5.0.1.1 及以下版本中存在基于 DOM 的跨站脚本漏洞(DOM-Based XSS),该漏洞源于 URL 路径名(URL Pathname)输入中缺乏足够的输入清理和输出转义。这使得未经身份验证的攻击者能够在网页中注入任意恶意 Web 脚本,当用户访问包含构造的恶意 URL 时,脚本将自动执行。利用此漏洞需要受害者具备 aio
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| smub | All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) | ≤ 5.0.1.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| smub | All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) | 0 ~ 5.0.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet