WordPress 的“社交媒体分享按钮与社交分享图标”插件(Social Media Share Buttons & Social Sharing Icons)在 3.0.1 及之前所有版本中,由于输入净化不足和输出转义不当,存在通过 URL 触发的反射型跨站脚本(Reflected XSS)漏洞。这使得未经身份验证的攻击者能够向页面注入任意 Web 脚本,当用户访问被注入的页面时,这些脚本将自动执行。利用该漏洞要求受害者使用移动设备用户代理(mobile user-agent),并点击微信分享图标;但一旦对话框
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| inisev | Social Media Share Buttons & Social Sharing Icons | ≤ 3.0.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| inisev | Social Media Share Buttons & Social Sharing Icons | 0 ~ 3.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet