WordPress 插件“Transliterator – Multilingual and Multi-script Text Conversion”存在存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞。该漏洞源于对用户输入内容缺乏足够的净化处理及输出转义,具体体现在插件版本 2.5.8 及更早版本中,攻击者可通过构造可预测的 {rstr_keep} 占位符,在评论内容中注入恶意脚本。 由于漏洞存在于评论保存时的净化机制之前,攻击者所提交的 HTML 标签和属性(例如 和 )
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ivijanstefan | Transliterator – Multilingual and Multi-script Text Conversion | ≤ 2.5.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ivijanstefan | Transliterator – Multilingual and Multi-script Text Conversion | 0 ~ 2.5.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet