WordPress 插件“HT Contact Form – Drag & Drop Form Builder”在所有截至 2.10.2 版本(包含 2.10.2)中均存在存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞,该漏洞源于富文本编辑器字段在输入 sanitization(清理)和输出转义方面存在不足。此漏洞允许未经身份验证的攻击者在网页中注入任意的 Web 脚本,当用户访问被注入的页面时,这些脚本将自动执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| htplugins | HT Contact Form – Drag & Drop Form Builder for WordPress | 0 ~ 2.10.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet