使用 PublishPress Authors 插件的 WordPress 中,“Co-Authors”、“Multiple Authors” 和 “Guest Authors” 功能在作者信息框中,通过作者信息页面上的“profile_fields_user_email_value_prefix”参数存在存储型跨站脚本(Stored Cross-Site Scripting)漏洞,影响所有包含 4.15.0 及之前的所有版本,原因在于输入数据未充分进行净化处理且输出未进行转义。这使得拥有“Author”权限或更高
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| publishpress | Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors | 0 ~ 4.15.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet