WordPress 插件 HT Contact Form – Drag & Drop Form Builder 中存在存储型基于 DOM 的跨站脚本(XSS)漏洞。该漏洞出现在所有 2.10.1 及之前版本中,原因是插件在“form_data”富文本字段中对用户输入的清理(sanitization)和输出转义(output escaping)不足。当用户保存或恢复草稿时,未经验证和清理的数据被直接嵌入页面,导致在用户访问包含恶意脚本的页面时,脚本将被执行。 攻击者可以无需认证即可注入任意网页脚本,从而实现跨站脚本攻
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| htplugins | HT Contact Form – Drag & Drop Form Builder for WordPress | ≤ 2.10.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| htplugins | HT Contact Form – Drag & Drop Form Builder for WordPress | 0 ~ 2.10.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet