WordPress 插件 WPFront Notification Bar 在 3.5.1 及以下版本中存在反射型跨站脚本(Reflected Cross-Site Scripting, XSS)漏洞。该漏洞源于调试日志输出路径(write_debug_logs)函数直接通过 将 的原始值反射到一个在 钩子上输出的 代码块中,且未进行任何 sanitization(清理)或 escaping(转义)处理。具体而言,插件的 方法中 URL 文本显示过滤器会产生一条日志条目:“Current URL is "%s"”,
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| syammohanm | WPFront Notification Bar | ≤ 3.5.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| syammohanm | WPFront Notification Bar | 0 ~ 3.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet