WordPress 的 WP Photo Album Plus 插件在所有不超过 9.3.03.002 版本的系统中,存在存储型跨站脚本(Stored Cross-Site Scripting)漏洞。该漏洞源于 REQUEST_URI 会话历史中未充分进行输入净化和输出转义,致使未认证的攻击者能够在网页中注入任意 Web 脚本。一旦用户访问被注入的页面,这些脚本便会自动执行。漏洞利用的关键在于: 函数虽然会剥离字面意义上的尖括号(即 和 ),但仍保留 HTML 实体编码;随后, 函数会将这些 HTML 实体静默地转
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| opajaap | WP Photo Album Plus | ≤ 9.3.03.002 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| opajaap | WP Photo Album Plus | 0 ~ 9.3.03.002 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet