WordPress 插件“Smash Balloon Social Post Feed”(一个简单的社交动态 feed 插件)在所有低于或等于 4.13.0 的版本中,存在存储型跨站脚本攻击(Stored XSS)漏洞。该漏洞源于对输入数据缺乏充分的 sanitization(净化)和输出时的 escaping(转义),攻击者可通过在关联的 Facebook 页面上发表评论消息,将恶意脚本注入到 Admin Builder 的预览页面中(利用 v-html 特性)。 由于缺乏输入验证和输出转义,未经认证的攻击者可以
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| smub | Smash Balloon Social Post Feed – Simple Social Feeds for WordPress | ≤ 4.13.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| smub | Smash Balloon Social Post Feed – Simple Social Feeds for WordPress | 0 ~ 4.13.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet