WordPress 的 Strong Testimonials 插件中存在一个存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞,影响范围包括 3.3.11 及更早的所有版本。该漏洞源于对 'platform_user_photo' 自定义字段在输入清理和输出转义方面的不足,使得未经身份验证的攻击者可以在网页中注入任意的 Web 脚本,每当用户访问被注入的页面时,这些脚本便会执行。 利用此漏洞的前提条件是:管理员已在公开的证词提交表单中添加了名为 'platform' 和 'pl
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wpchill | Strong Testimonials | 0 ~ 3.3.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet