WordPress 插件“EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents”在所有版本(包括 4.6.5 及更早版本)中易受反射型跨站脚本(Reflected XSS)攻击,原因是‘unique’参数的输入过滤和输出转义不足。这使得未经身份验证的攻击者能够通过诱使用户执行某些操作(例如点击链接),从而在相关页面中注入任意 Web 脚本。这是一个回归性缺陷:在
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wpdevteam | EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents | ≤ 4.6.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wpdevteam | EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents | 0 ~ 4.6.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet