WordPress 的 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns 插件在 6.4.5 及更早版本中存在存储型跨站脚本(Stored XSS)漏洞。该漏洞源于对 Google Map 块中“marker”属性的标题和内容值缺乏充分的输入净化和输出转义。这些值以 JSON 格式存储,随后在前端脚本的 InfoWindow 内容构建器中被解码并直接拼接到原始 HTML 中。这使得拥有贡献者(Contributor)级
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wpdevteam | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns | ≤ 6.4.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wpdevteam | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns | 0 ~ 6.4.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet