WordPress 的 Zero Spam 插件在 5.7.10 及更早版本中,由于输入数据未充分净化且输出未正确转义,存在通过 Contact Form 7 集成中的嵌套 POST 数组键实现存储型跨站脚本攻击(Stored XSS)的漏洞。 该漏洞允许未认证的 attackers 向页面注入任意 Web 脚本,当用户访问被注入的页面时,这些脚本将被执行。攻击载荷通过提交一个包含任意 HTML 或 JavaScript 的嵌套 POST 数组键的 Contact Form 7 请求来投递。PHP 会将该字段名解析
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| bmarshall511 | Zero Spam for WordPress | ≤ 5.7.10 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| bmarshall511 | Zero Spam for WordPress | 0 ~ 5.7.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet