WordPress 的 GeoDirectory – WP 商业目录插件及分类广告列表目录插件存在存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞。该漏洞存在于所有版本直至包括 2.8.181 在内,原因是插件对文本类型的自定义字段(例如“电话”字段)缺乏充分的输入清洗和输出转义。这使得具备订阅者及以上权限的认证攻击者能够在页面上注入任意 Web 脚本,当其他用户访问被注入脚本的页面时,这些恶意脚本便会执行。 攻击者需通过 AJAX 接口 ,将恶意载荷存储在文本类型的自定义字段
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| paoltaia | GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | ≤ 2.8.181 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| paoltaia | GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | 0 ~ 2.8.181 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet