WordPress 的 ProfilePress 插件(功能包括付费会员管理、电子商务、用户注册表单、登录表单、用户个人资料及内容权限控制)在所有版本(最高至 4.17.4)中存在反射型跨站脚本(XSS)漏洞。该漏洞源于对 文件名参数的输入清理和输出转义不足,导致未认证的攻击者能够向网页中注入任意 Web 脚本。如果攻击者成功诱使用户执行某些操作(例如点击恶意链接),这些脚本便会在用户浏览器中执行。 此漏洞可通过任何托管 ProfilePress 选项卡小部件的页面进行利用:攻击者只需在构造的 POST 请求中,为
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| properfraction | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress | 0 ~ 4.17.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet