WordPress 插件 Greenshift – 动画和页面构建器块存在反射型跨站脚本(XSS)漏洞,该漏洞影响所有 13.2.0 及更早版本。漏洞原因是缺乏足够的输入清理和输出转义。通过 动态占位符,未认证的攻击者可以在页面中注入任意 Web 脚本,当用户被诱骗执行某些操作(例如点击恶意链接)时,脚本将被执行。 此漏洞的触发需要满足以下条件: 1. 站点管理员在某个元素块的“自定义 JavaScript(Custom JS)”字段中配置了包含 占位符; 2. 该 JavaScript 代码中包含关键字 ; 3.
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wpsoul | Greenshift – animation and page builder blocks | ≤ 13.2.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wpsoul | Greenshift – animation and page builder blocks | 0 ~ 13.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet