WordPress 的 Qi Addons for Elementor 插件在 1.11 及之前所有版本中,由于输入验证不足和输出转义缺失,存在通过 's' 参数触发的反射型跨站脚本(Reflected XSS)漏洞。这使得未经身份验证的攻击者能够向页面注入任意 Web 脚本,一旦用户访问该被注入的页面,这些脚本将会自动执行。要利用此漏洞,需满足以下条件:目录(Table of Contents)小部件被放置在一个会在 WordPress 搜索结果页上渲染的模板中(例如全站页眉或页脚模板),并且 “将目录限制在主页
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| qodeinteractive | Qi Addons For Elementor | ≤ 1.11 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| qodeinteractive | Qi Addons For Elementor | 0 ~ 1.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet