WordPress 插件“No External Links”在 5.2.0 及更早版本中存在存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞。该漏洞源于对 重定向过程中日志 URL 的输入 sanitization(净化)和输出转义(escaping)不足。攻击者无需身份认证即可在页面中注入任意 Web 脚本,当用户访问被注入的页面时,这些脚本将被执行。此漏洞仅在管理员在插件设置中启用了“链接编码:Base64”(Link Encoding: Base64)选项时才可被利用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mihdan | No External Links | 0 ~ 5.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet