WordPress 中的 Aurora Heatmap 插件存在存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞。该漏洞存在于 1.7.2 及所有更低版本中,原因是插件在处理 ‘url’ 参数时缺乏足够的输入净化和输出转义。攻击者无需身份认证即可在页面中注入任意 Web 脚本,当管理员用户点击被植入的 heatmap 链接时,这些恶意脚本将会执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| r3098 | Aurora Heatmap | 0 ~ 1.7.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet