WordPress 插件“Visitors Traffic Real Time Statistics Pro”存在未认证的存储型跨站脚本(XSS)漏洞,该漏洞影响所有 11.22 及更早版本。攻击者可通过 AJAX 操作的 参数利用此漏洞。该 AJAX 动作已注册为允许未登录用户调用(即 ),并在接收 时未进行任何数据清理,直接以原始形式存储到数据库表 的 字段中。当管理员打开插件的仪表盘时,“按标题查看流量”(Traffic by Title)数据表会以 方式渲染该已存储的值,且未进行输出转义,从而导致任意 Ja
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wp-buy | Visitor Traffic Real Time Statistics pro | ≤ 11.22 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wp-buy | Visitor Traffic Real Time Statistics pro | 0 ~ 11.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet