WordPress 文本转语音插件 GSpeech TTS 在 3.22.0 及更早版本中存在存储型跨站脚本(Stored XSS)漏洞。该漏洞是由于输入清理不足和输出转义不充分所导致。攻击者无需身份验证即可在页面中注入任意 Web 脚本,当用户访问被注入脚本的页面时,脚本便会自动执行。 此类 xSS 风格的绕过手段可绕过 WordPress 评论系统的 kses 过滤机制,因为恶意负载仅使用 kses 允许的标签和属性进行存储;但当插件在请求时通过输出缓冲回调函数重写已渲染的 HTML 时,恶意的事件处理器和样式
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| creative-solutions-1 | GSpeech TTS – WordPress Text To Speech Plugin | ≤ 3.22.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| creative-solutions-1 | GSpeech TTS – WordPress Text To Speech Plugin | 0 ~ 3.22.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet