WordPress 插件 GeoDirectory(一个 WP 商业目录插件和分类广告目录插件)在 2.8.183 及以下所有版本中,存在一个因输入清理和输出转义不足导致的信息存储型跨站脚本(Stored XSS)漏洞。该漏洞存在于 参数中。这使得具有订阅者级别及以上权限的已认证攻击者能够在网页中注入任意 Web 脚本,每当用户访问被注入的页面时,这些脚本就会执行。之所以可能发生这种情况,是因为 AJAX 保存处理程序仅验证文章作者身份和一个 nonce(一次性令牌),而没有进行其他能力检查,从而允许任何拥有目录条
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| paoltaia | GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | ≤ 2.8.183 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| paoltaia | GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | 0 ~ 2.8.183 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet