WordPress 的 DoFollow Case by Case 插件在所有版本(包括 3.6.0 及更早版本)中存在存储型跨站脚本漏洞(Stored Cross-Site Scripting, XSS),该漏洞源于评论内容在输入时缺乏充分的净化处理以及输出时未进行正确的转义。这使得未经验证身份的攻击者能够在页面中注入任意 Web 脚本,当用户访问被注入脚本的页面时,脚本便会执行。尽管评论审核机制可能会延迟攻击的生效,但并不能阻止攻击的成功——一旦管理员批准了一条表面上无害的评论,存储的恶意代码将在每个后续访问该
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| apasionados | DoFollow Case by Case | ≤ 3.6.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| apasionados | DoFollow Case by Case | 0 ~ 3.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet