WordPress 插件 Ultimate Member(功能包括用户个人资料、注册、登录、会员目录、内容限制及会员管理)存在存储型跨站脚本(XSS)漏洞。该漏洞影响所有 2.13.1 及更早版本,原因是插件对 参数缺乏充分的输入清理和输出转义。这使得未经身份验证的攻击者能够在页面中注入任意 Web 脚本,当用户访问被植入恶意脚本的页面时,这些脚本便会执行。恶意负载会通过 函数存储在注册用户的 'submitted' 用户元数据(usermeta)中,仅在管理员通过 wp-admin 的用户模态窗口打开受影响的特定
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ultimatemember | Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin | 0 ~ 2.13.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet