WordPress 和 WooCommerce 的 “Filter Everything” 插件在 1.9.6 及以下版本中存在反射型跨站脚本(Reflected Cross-Site Scripting, XSS)漏洞。该漏洞源于 函数中对输入清理和输出转义处理不足。 具体来说,该函数通过调用 从 中读取查询参数,并使用 进行 URL 解码,再通过 (一个 WordPress 核心函数,默认不进行值编码,即 )重新拼接 URL。生成的 URL 中包含未转义的特殊字符,随后通过 被注入到 HTML 属性中,且未使用
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| stepasyuk | Filter Everything — WordPress & WooCommerce Filters | ≤ 1.9.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| stepasyuk | Filter Everything — WordPress & WooCommerce Filters | 0 ~ 1.9.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet